High priority
SAP security note 1613621, "Missing Authorization Check in Function Module HR_DK_READ_TEXTS", is a note released on January 10, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can utilize functions of the Function Module HR_DK_READ_TEXTS without the necessary authorization checks. This vulnerability may lead to an escalation of privileges within the system.
Solution
SAP has deactivated obsolete code within the Function Module HR_DK_READ_TEXTS to address this issue. These modifications will not affect existing applications since the Function Module is not referenced in any specific application.
Reason and prerequisites
The Function Module HR_DK_READ_TEXTS lacks adequate authorization checks to verify if an authenticated user has the rights to access certain functionalities. This omission can result in unintended system behavior and potential security breaches.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
References
Affected components
- SAP_HR (46C)
- SAP_HRCDK (470, 500, 600, 604)
Full note on SAP: SAP Support Launchpad note 1613621
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
