SAP security note 1839758, "Missing authorization check in CA-GTF-SCM", is a note released on May 14, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can exploit functions of CA-GTF-SCM without proper authorization checks, potentially leading to an escalation of privileges.
Solution
Apply the provided corrections to address the missing authorization checks.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Affected components
- CA-GTF-SCM 46C
- CA-GTF-SCM 620
- CA-GTF-SCM 640
- CA-GTF-SCM 700-702
- CA-GTF-SCM 710-711
- CA-GTF-SCM 730-731
- CA-GTF-SCM 740
Full note on SAP: SAP Support Launchpad note 1839758
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
