SAP Security Note
HotNews
SAP security note 1785761, "Missing authorization check in RFC", is a note released on 12.02.2013. Below are the symptom and the SAP recommended solution.
Description
Symptom
An authenticated user can use functions of an SAP NetWeaver Server ABAP to which access should be restricted. This may result in an escalation of privileges.
Solution
To address this vulnerability, import the kernel with the patch level specified under "SP Patch Level" in the support package patches section.
Reason and prerequisites
There are insufficient authorization checks for verifying an authenticated user's permissions to access certain functions. This oversight can lead to undesired system behavior.
Affected systems: NetWeaver releases 7.00 and 7.01; Kernel versions 7.20 and 7.21 (downward compatible).
CVSS
Score 9.0 Vector: AV:N/AC:L/AU:S/C:C/I:C/A:C
References
- SAP Note 1594405 – ST-SER 2010_1: Maintenance of SAP Kernel issues
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
- RFC_NO_AUTHORITY Short dumps after kernel update
Full note on SAP: SAP Support Launchpad note 1785761
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
