SAP security note 2025794, “Missing authority check in CA-MDG-APP-ISS”, is a note. Below is the security information published by SAP for this note.
Description
Symptom
An authenticated user can use functions of CA-MDG-APP-ISS (Integrated Self Service) to which access should be restricted. This may result in an escalation of privileges.
Reason and prerequisites
CA-MDG-APP-ISS does not contain authorization checks for verifying an authenticated user's authorization to access some of its remotely called functions. This may result in undesired system behavior.
Solution
Implement the attached code correction or the relevant support package.
Full note on SAP: SAP Support Launchpad note 2025794
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
