High priority
SAP security note 2155614, "Missing authorization check in SD-SLS, SD-CAS and SD-MD-AM-CMI", was released on August 1, 2018. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can utilize functions in SD-SLS, SD-CAS, and SD-MD-AM-CMI without proper authorization checks, potentially leading to privilege escalation.
Solution
Implement the provided code corrections to enforce proper authorization checks. Detailed correction instructions are available here.
Reason and prerequisites
These components lack necessary authorization checks for certain functions, which may result in undesired system behavior.
- SAP Note 1569388 for various SAP_BASIS versions (700 to 730).
Full note on SAP: SAP Support Launchpad note 2155614
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
