SAP Security Note
High priority
SAP security note 1842218, "Missing authorization check in PS", is a program error note released on 11.06.2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of PS to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the code corrections via transaction SNOTE.
Reason and prerequisites
PS does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This omission may result in undesired system behavior.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Affected components
- SAP_APPL (versions 600 to 617)
- PI (versions 2004_1_46B to 2004_1_500)
Full note on SAP: SAP Support Launchpad note 1842218
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
