Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in IS-A-DP, SAP security note 2000401

SAP Note 2000401SAP Security NoteHigh priority

SAP security note 2000401, "Missing authorization check in IS-A-DP", is a program error note released on 13.01.2015. Below are the symptom, SAP recommended solution and the affected software components.

ComponentIndustry-Specific Components > Automotive > Dealer Portal (IS-A-DP)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on13.01.2015
LanguageEnglish

Description

Symptom

An authenticated user can use functions of IS-A-DP to which access should be restricted. This may result in an escalation of privileges.

Solution

Implement support package or correction instructions.

Reason and prerequisites

IS-A-DP does not contain required checks against a positive set of allowed functions (i.e., whitelist) during execution of these functions. This is required to verify that authenticated users are allowed to access these functions. The missing check may result in undesired system behavior.

CVSS

Score 6.0 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Affected components

  • ECC-DIMP 604
  • ECC-DIMP 605
  • ECC-DIMP 606
  • ECC-DIMP 616
  • ECC-DIMP 617

Full note on SAP: SAP Support Launchpad note 2000401

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More