Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing RFC authorization in eCATT Extended Computer Aided Test Tool, SAP security note 2053043

SAP Note 2053043
SAP Security Note
Medium priority

SAP security note 2053043, "Missing RFC authorization in eCATT Extended Computer Aided Test Tool", is a program error note released on 12.05.2015. Below are the symptom and the SAP recommended solution.

ComponentBasis Components > Test Workbench > Testing Tools > eCATT Extended Computer Aided Test Tool
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on12.05.2015
LanguageEnglish

Description

Symptom

An authenticated user can use an RFC function of BC-TWB-TST-ECA to which access should be restricted. This may result in an escalation of privileges.

Solution

Implement the correction provided in this note.

Reason and prerequisites

BC-TWB-TST-ECA does not contain an authorization check for verifying an authenticated RFC user’s authorization to one function. This may result in undesired system behavior.

Full note on SAP: SAP Support Launchpad note 2053043

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More