SAP Security Note
High priority
SAP security note 2251619, "Missing authorization check in Audit Functions of DBA Cockpit", is released on 12.01.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
The DBA Cockpit infrastructure contains function modules for auditing, which are not protected by authority checks.
Solution
An authorization check of authorization object S_RZL_ADM will be added to the affected functions. The related changes will be delivered via a support package. You can also implement the changes in advance by applying the assigned correction instructions.
Reason and prerequisites
DBA Cockpit infrastructure for auditing does not contain authorization checks for verifying an authenticated user's authorization to access certain functions. This may result in undesired system behavior.
CVSS
Score 4.9 / 10 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N
Full note on SAP: SAP Support Launchpad note 2251619
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
