Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in Audit Functions of DBA Cockpit, SAP security note 2251619

SAP Note 2251619
SAP Security Note
High priority

SAP security note 2251619, "Missing authorization check in Audit Functions of DBA Cockpit", is released on 12.01.2016. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Database Interface, Database Platforms > DB2 Universal Database for Unix / NT > CCMS/Database Monitors
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on12.01.2016

Description

Symptom

The DBA Cockpit infrastructure contains function modules for auditing, which are not protected by authority checks.

Solution

An authorization check of authorization object S_RZL_ADM will be added to the affected functions. The related changes will be delivered via a support package. You can also implement the changes in advance by applying the assigned correction instructions.

Reason and prerequisites

DBA Cockpit infrastructure for auditing does not contain authorization checks for verifying an authenticated user's authorization to access certain functions. This may result in undesired system behavior.

CVSS

Score 4.9 / 10 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Full note on SAP: SAP Support Launchpad note 2251619

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More