SAP Security Note
Medium priority
SAP security note 2029526, "Missing authorization check in CA-CL", is a note released on 11.11.2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of CA-CL to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement correction instructions.
Reason and prerequisites
CA-CL does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may lead to undesired system behavior.
References
Affected components
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
- SAP_APPL 606
- SAP_APPL 616
- SAP_APPL 617
Full note on SAP: SAP Support Launchpad note 2029526
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
