SAP security note 1997734, “Missing authorization check in RFC runtime”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
This security note has been updated. For more detailed information, see Security Note 2205421.
An authenticated user can use functions of RFC runtime to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply Support Package or correction instructions. The usage of authorization object S_RFCACL is corrected.
CVSS
Score 6.0 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 1997734
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
