Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in BC-SRV-BRF, SAP security note 1828883

SAP Note 1828883
SAP Security Note
High priority

SAP security note 1828883, "Missing authorization check in BC-SRV-BRF", is a program error note released on 14.05.2013. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBC-SRV-BRF (Basis Components > Basis Services/Communication Interfaces > Business Rule Framework (For BRF+, use BC-SRV-BR))
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on14.05.2013
LanguageEnglish

Description

Symptom

An authenticated user can use functions of BC-SRV-BRF to which access should be restricted. This may result in an escalation of privileges.

Solution

Implement the correction instructions or import the specified Support Package.

Reason and prerequisites

BC-SRV-BRF does not contain authorization checks for checking an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.

CVSS

Score 4.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:P

Affected components

  • SAP_BASIS 710 to 730
  • SAP_BASIS 731
  • SAP_BASIS 740
  • SAP_ABA 640
  • SAP_ABA 700 to 702

Full note on SAP: SAP Support Launchpad note 1828883

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More