Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in SV_SMG-ASU, SAP security note 1942424

SAP Note 1942424
High priority

SAP security note 1942424, “Missing authorization check in SV_SMG-ASU”, is a program error note released on January 14, 2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentST-PI
CategoryProgram error
PriorityCorrection with high priority
StatusReleased for Customer
Released onJanuary 14, 2014

Description

Symptom

An authenticated user can use functions of SV-SMG-ASU to which access should be restricted. This may result in an escalation of privileges.

Solution

Implement the attached correction instruction or install the assigned support package. The correction deactivates an obsolete but critical program.

Reason and prerequisites

SV-SMG-ASU does not contain authorization checks for verifying an authenticated user’s permissions to access certain functions. This oversight may lead to undesired system behavior.

Affected components

  • ST-PI versions from 2008_1_46C to 2008_1_710

Full note on SAP: SAP Support Launchpad note 1942424

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More