SAP Security Note
SAP security note 1735308, "Security issues for report TAB_INTO_AUTH_GRP", is a note released on 05.11.2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of BC-CUS-TOL-ALO to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the corrections provided in the Note.
Reason and prerequisites
BC-CUS-TOL-ALO does not contain authorization checks for verifying an authenticated user’s permissions to access certain functions. This oversight may lead to undesired system behavior.
References
Affected components
- SAP_BASIS 620 to 640
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 730
- SAP_BASIS 731
- SAP_BASIS 740
Full note on SAP: SAP Support Launchpad note 1735308
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
