SAP Security Note
High priority
SAP security note 1792354, "Missing authorization check in DMIS_EXT", is a program error note released on February 11, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of DMIS_EXT to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement automatic correction instructions in all systems that contain software component DMIS_EXT.
Reason and prerequisites
DMIS_EXT does not contain authorization checks for verifying an authenticated user's authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Affected components
- DMIS_EXT from 2007_1_46C to 2007_1_46C
- DMIS_EXT from 2007_1_620 to 2007_1_620
- DMIS_EXT from 2007_1_640 to 2007_1_640
- DMIS_EXT from 2007_1_700 to 2007_1_700
- DMIS_EXT from 2007_1_730 to 2007_1_730
- DMIS_EXT from 2007_1_731 to 2007_1_731
Full note on SAP: SAP Support Launchpad note 1792354
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



