SAP security note 1658568, "Missing access restrictions", released on 14.02.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An unauthenticated user can use functions of a security service to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply the fix according to the information under the Validity and SP Patch Level tabs of this note.
Reason and prerequisites
The security service does not contain restrictions to access some of its functions. This may result in an undesired system behavior.
Affected components
- Basis Components > NetWeaver Application Server Java > Security, User Management > Logon, SSO (BC-JAS-SEC-LGN)
Full note on SAP: SAP Support Launchpad note 1658568
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




