Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization checks in Report Launchpad component, SAP security note 2267789

SAP Note 2267789
Medium priority

SAP security note 2267789, "Missing Authorization Checks in Report Launchpad Component", is released on April 12, 2016. Below are the symptom, SAP recommended solution and the affected software components.

PriorityCorrection with medium priority
StatusReleased for Customer
Released onApril 12, 2016

Description

Symptom

SAP has released Security Note 2267789 addressing a critical issue in the Report Launchpad component. The Report Launchpad was found missing necessary authorization checks, which could allow authenticated users to escalate their privileges. This vulnerability poses risks such as unauthorized access to restricted functionalities and data manipulation.

Solution

SAP has implemented proper authorization checks in the following programs:

  • APB_LAUNCHPAD_SELECTION
  • APB_LAUNCHPAD_SELECTION_DISP
  • APB_LAUNCHPAD_PARAMETRIZED

CVSS

Score 6.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected components

  • SAP_UI: 740
  • SAP_BASIS: 710, 711, 730, 731
  • SAP_ABA: 700, 701, 702

Full note on SAP: SAP Support Launchpad note 2267789

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More