Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in DMIS_EXT, SAP security note 1813734

SAP Note 1813734
SAP Security Note
High priority

SAP security note 1813734, "Missing authorization check in DMIS_EXT," is a program error note released on 11.03.2013. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCross-Application Components > Test Data Migration Server (SAP TDMS) > Business Process Library (CA-TDM-BPL)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on11.03.2013
LanguageEnglish

Description

Symptom

An authenticated user can use functions of DMIS_EXT to which access should be restricted. This may result in an escalation of privileges.

Solution

Implement the automatic correction instruction in every system that contains software component DMIS_EXT.

Reason and prerequisites

DMIS_EXT does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

Affected components

  • DMIS_EXT 2007_1_620
  • DMIS_EXT 2007_1_640
  • DMIS_EXT 2007_1_700
  • DMIS_EXT 2007_1_730
  • DMIS_EXT 2007_1_731

Full note on SAP: SAP Support Launchpad note 1813734

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More