Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in SD-SLS, SD-CAS and SD-MD-AM-CMI, SAP security note 2155614

SAP Note 2155614
High priority

SAP security note 2155614, "Missing authorization check in SD-SLS, SD-CAS and SD-MD-AM-CMI", was released on August 1, 2018. Below are the symptom and SAP recommended solution.

ComponentSales and Distribution (SD-SLS)
PriorityCorrection with high priority
StatusReleased for Customer
Released onAugust 1, 2018

Description

Symptom

An authenticated user can utilize functions in SD-SLS, SD-CAS, and SD-MD-AM-CMI without proper authorization checks, potentially leading to privilege escalation.

Solution

Implement the provided code corrections to enforce proper authorization checks. Detailed correction instructions are available here.

Reason and prerequisites

These components lack necessary authorization checks for certain functions, which may result in undesired system behavior.

  • SAP Note 1569388 for various SAP_BASIS versions (700 to 730).

Full note on SAP: SAP Support Launchpad note 2155614

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More