SAP Security Note
High priority
SAP security note 2170931, “Missing authorization check in SAP Switch Framework”, is a program error note released on 14.07.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of SAP Switch Framework to which access should be restricted. This may result in an escalation of privileges.
Solution
Under certain circumstances, the authorization S_SWITCH is not correctly checked during the activation of a switch. This issue is addressed with this SAP Note.
Please apply the Support Package mentioned in this SAP Note or follow the respective correction instructions.
Reason and prerequisites
SAP Switch Framework does not contain authorization checks for verifying an authenticated user’s permissions to access certain functions. This oversight may lead to undesired system behavior.
Full note on SAP: SAP Support Launchpad note 2170931
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
