SAP security note 1889999, "Missing Authorization Check in LCAPPS DP". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can exploit functions of LCAPPS DP without proper authorization checks, potentially leading to an escalation of privileges. This vulnerability arises because certain ABAP objects in LCAPPS DP lack necessary authorization validations, resulting in undesired system behavior.
Solution
Apply the correction instructions provided in this note to mitigate the vulnerability.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Affected components
- SCMAPO 713
- SCM 700, 701, 702, 712
- LCAPPS 2005_700, 2006_700, 2006_710
Full note on SAP: SAP Support Launchpad note 1889999
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
