SAP security note 2027145, "Missing authorization check in LO-MD-MG", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of LO-MD-MG to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the provided correction instructions.
Reason and prerequisites
LO-MD-MG does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
References
- SAP Note 2078596 – Further improvements for RFC security
Affected components
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
- SAP_APPL 606
- SAP_APPL 616
- SAP_APPL 617
Full note on SAP: SAP Support Launchpad note 2027145
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
