SAP security note 1917381, “Missing authorization check in Profile Maintenance”, is a note. Below is the security information published by SAP for this note.
Description
Symptom
An authenticated user can use functions of Profile Maintenance to which access should be restricted. This may result in an escalation of privileges.
Reason and prerequisites
Profile Maintenance does not contain authorization checks for checking an authenticated user's authorization to access some of its functions. This may result in undesired system behavior.
Solution
Authorization check on S_RZL_ADM is added to these functions.
- Read and write access is checked for activity "01"
- Read-only access in case of an access through an RFC connection checks for activity "03"
Please implement the support package mentioned in this note or implement the corrections of SAP Note 1580244, and apply the respective correction instruction of this note.
Remark for customers that have installed Support Package 5 of SAP_BASIS 740 (SAPKB74005): Version 2 of this note cannot be implemented if version 1 is already implemented. Do not try to de-implement version 1 in this case.
Full note on SAP: SAP Support Launchpad note 1917381
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
