Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization Check in DI_CMS (BC-CTS-CMS), SAP security note 1831022

SAP Note 1831022

SAP security note 1831022, "Missing Authorization Check in DI_CMS (BC-CTS-CMS)", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

An authenticated user can use functions of DI_CMS (BC-CTS-CMS) to which access should be restricted. This may result in an escalation of privileges.

Solution

Coding gets completed by authorization checks when applying one of the following Support Package Stacks for software component DI_CMS:

  • 7.00 SP 29
  • 7.01 SP 14
  • 7.02 SP 14
  • 7.11 SP 13
  • 7.30 SP 10
  • 7.31 SP 8
  • 7.40 SP 3

In version 7.20, there are no further SP Stacks delivered. The change is contained in SP 9 Patch 1.

If you use SAP-delivered UME roles to operate your NWDI, no further steps are required (e.g., SAP_DI_ADMINISTRATOR, SAP_DI_DEVELOPER, or in some releases NWDI.Administrator, NWDI.Developer).

If you created your own UME roles to operate NWDI, you need to adapt them and assign new actions to them. For details, see the help documentation of your AS Java Release under "Authorizations in Change Management Service" and "Roles in the Change Management Service".

Reason and prerequisites

DI_CMS (BC-CTS-CMS) does not contain authorization checks for verifying an authenticated user's authorization to access some of its functions. This may result in undesired system behavior.

CVSS

Score 5.5 Vector: AV:N/AC:L/AU:S/C:P/I:P/A:N

References

Full note on SAP: SAP Support Launchpad note 1831022

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More