Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check when branching to phrase mgmt, SAP security note 1673016

SAP Note 1673016SAP Security NoteHigh priority

SAP security note 1673016, "Missing authorization check when branching to phrase mgmt", is a program error note released on 08.01.2013. Below are the symptom, SAP recommended solution and the affected software components.

ComponentEnvironment, Health, and Safety / Product Compliance > Dangerous Goods Management > Template and One-Time Material Processing
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on08.01.2013
LanguageEnglish

Description

Symptom

Component: Dangerous Goods Management. Module: Template and one-time material processing.

An authenticated user can use functions of phrase management to which access should be restricted. This may result in an escalation of privileges.

Solution

This correction ensures that the authorization for the transaction for phrase processing is checked. The "Reference to Support Packages" section specifies the Support Packages that contain the corrections. Alternatively, you can implement the attached correction instructions.

Reason and prerequisites

Reason: Dangerous Goods Management does not contain authorization checks for checking an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.

Prerequisites: For information about the validity of the corrections, see the correction instructions.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

References

Affected components

  • EA-APPL versions 110, 200, 500, 600, 602, 603, 604, 605, 606

Full note on SAP: SAP Support Launchpad note 1673016

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More