SAP security note 1831022, "Missing Authorization Check in DI_CMS (BC-CTS-CMS)", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of DI_CMS (BC-CTS-CMS) to which access should be restricted. This may result in an escalation of privileges.
Solution
Coding gets completed by authorization checks when applying one of the following Support Package Stacks for software component DI_CMS:
- 7.00 SP 29
- 7.01 SP 14
- 7.02 SP 14
- 7.11 SP 13
- 7.30 SP 10
- 7.31 SP 8
- 7.40 SP 3
In version 7.20, there are no further SP Stacks delivered. The change is contained in SP 9 Patch 1.
If you use SAP-delivered UME roles to operate your NWDI, no further steps are required (e.g., SAP_DI_ADMINISTRATOR, SAP_DI_DEVELOPER, or in some releases NWDI.Administrator, NWDI.Developer).
If you created your own UME roles to operate NWDI, you need to adapt them and assign new actions to them. For details, see the help documentation of your AS Java Release under "Authorizations in Change Management Service" and "Roles in the Change Management Service".
Reason and prerequisites
DI_CMS (BC-CTS-CMS) does not contain authorization checks for verifying an authenticated user's authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 5.5 Vector: AV:N/AC:L/AU:S/C:P/I:P/A:N
References
Full note on SAP: SAP Support Launchpad note 1831022
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




