Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in JIT, SAP security note 1812645

SAP Note 1812645

SAP security note 1812645, “Missing authorization check in JIT”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An authenticated user can utilize JIT functions without appropriate authorization, resulting in possible escalation of privileges.

Solution

Implement the corrections provided in the SAP Security Note to enforce proper authorization checks within the JIT component.

Reason and prerequisites

The JIT component does not perform necessary authorization checks to verify if an authenticated user has the permissions required to access certain functions. This lack of verification can lead to unintended system behavior and potential security breaches.

CVSS

Score 4.9 Vector: AV:N/AC:M/AU:S/C:N/I:P/A:P

References

Affected components

  • ECC-DIMP: 500 to 617

Full note on SAP: SAP Support Launchpad note 1812645

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More