Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in CRM-MW-ADP functions, SAP security note 1906568

SAP Note 1906568
SAP Security Note
Medium priority

SAP security note 1906568, "Missing authorization check in CRM-MW-ADP functions", is a program error note released on 12.11.2013. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Middleware > Middleware Adapter
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on12.11.2013
LanguageEnglish

Description

Symptom

An authenticated user can use functions of CRM-MW-ADP to which access should be restricted. This may result in an escalation of privileges.

Solution

Implement the provided support package or follow the correction instructions. No whitelist is required.

Reason and prerequisites

CRM-MW-ADP does not contain authorization checks for verifying an authenticated user's authorization to access certain functions. This may result in undesired system behavior.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

References

Affected components

  • PI_BASIS (version 701 to 740+)

Full note on SAP: SAP Support Launchpad note 1906568

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More