SAP Security Note
Medium priority
SAP security note 1944155, "Missing authorization check in report RKEDELE1", is a program error note released on 01.08.2018. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can execute the report RKEDELE1, to which access should be restricted.
Solution
Implement the correction instructions or import the Support Package relevant to your release.
The report RKEDELE1 is checked against the authorization object K_KEA_TC with the activity 02 (Change).
Reason and prerequisites
The report RKEDELE1 does not contain authorization checks for validating an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
Full note on SAP: SAP Support Launchpad note 1944155
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
