SAP security note 1992114, “Missing authorization check in SV-SMG-TWB-BCA”, is a note released on 12.08.2014. Below is the security information published by SAP for this note.
Description
An authenticated user can use functions of SV-SMG-TWB-BCA to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply the attached correction instructions to your managed system, or install in the corresponding support package.
Full note on SAP: SAP Support Launchpad note 1992114
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
