Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in System Trace, SAP security note 2065073

SAP Note 2065073
SAP Security Note
High priority

SAP security note 2065073, “Missing authorization check in System Trace”, released on January 13, 2015. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Client/Server Technology > Low Level Layers (BC-CST-LL)
PriorityHigh priority
TypeSAP Security Note
Version3
Released onJanuary 13, 2015

Description

Symptom

An authenticated user can use functions of transaction ST01 (System Trace) to which access should be restricted. This may result in an escalation of privileges.

Solution

To address this issue, install the corresponding Support Package or implement the provided Correction Instructions.

The solution checks for S_ADMI_FCD authorization with the value “ST0R”.

Reason and prerequisites

Transaction ST01 does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This lack of checks may lead to undesired system behavior and potential privilege escalation.

CVSS

Score 4.9 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:P

Affected components

  • SAP_BASIS versions 700 to 702
  • SAP_BASIS versions 710 to 730
  • SAP_BASIS version 731
  • SAP_BASIS version 740

Full note on SAP: SAP Support Launchpad note 2065073

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More