SAP security note 1673016, "Missing authorization check when branching to phrase mgmt", is a program error note released on 08.01.2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Component: Dangerous Goods Management. Module: Template and one-time material processing.
An authenticated user can use functions of phrase management to which access should be restricted. This may result in an escalation of privileges.
Solution
This correction ensures that the authorization for the transaction for phrase processing is checked. The "Reference to Support Packages" section specifies the Support Packages that contain the corrections. Alternatively, you can implement the attached correction instructions.
Reason and prerequisites
Reason: Dangerous Goods Management does not contain authorization checks for checking an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
Prerequisites: For information about the validity of the corrections, see the correction instructions.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
References
Affected components
- EA-APPL versions 110, 200, 500, 600, 602, 603, 604, 605, 606
Full note on SAP: SAP Support Launchpad note 1673016
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
