SAP security note 2031117, “Missing authorization check in PLM-RM-TRL”, is a note. Below is the security information published by SAP for this note.
Description
Symptom
An authenticated user can access functions within PLM-RM-TRL that should be restricted, potentially leading to an escalation of privileges.
Reason and prerequisites
Reason: PLM-RM-TRL lacks necessary authorization checks for certain functions, which may result in undesired system behavior.
Prerequisite: Before implementing this correction, ensure that SAP Note 1882417 is fully applied.
Solution
Implement the correction instructions provided in SAP Note 2031117 for SNOTE or access the PDF version.
References
- SAP Note 2078596: Further improvements for RFC security
- SAP Note 1882417: External check for Remote Function Call
Full note on SAP: SAP Support Launchpad note 2031117
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
