SAP security note 1597598, “Missing authorization check in ICF”, is a note. Below are the symptom, SAP recommended solution, CVSS score and references.
Description
Symptom
An authenticated user can use functions in the Internet Communication Framework (ICF) to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the attached source code corrections or import the relevant Support Package.
Reason and prerequisites
ICF does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may result in undesired system behavior.
CVSS
Score 2.1 Vector: AV:N/AC:H/AU:S/C:N/I:P/A:N
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1597598
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
