SAP Security Note
SAP security note 1821306, “End User logon authentication is bypassed in Access Request”, is a note released on April 9, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
End User logon authentication is bypassed under certain conditions. Users are able to log in to the application by providing any invalid username/password.
Solution
Implement the attached correction instructions to address the authentication bypass issue.
Reason and prerequisites
Improper error handling in certain cases leads to undesired results, allowing authentication bypass.
References
- 1805500 – Master Note for SAP Access Control 10.0 – Support Pack 12
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Full note on SAP: SAP Support Launchpad note 1821306
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




