Medium priority
SAP security note 2267789, "Missing Authorization Checks in Report Launchpad Component", is released on April 12, 2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP has released Security Note 2267789 addressing a critical issue in the Report Launchpad component. The Report Launchpad was found missing necessary authorization checks, which could allow authenticated users to escalate their privileges. This vulnerability poses risks such as unauthorized access to restricted functionalities and data manipulation.
Solution
SAP has implemented proper authorization checks in the following programs:
- APB_LAUNCHPAD_SELECTION
- APB_LAUNCHPAD_SELECTION_DISP
- APB_LAUNCHPAD_PARAMETRIZED
CVSS
Score 6.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected components
- SAP_UI: 740
- SAP_BASIS: 710, 711, 730, 731
- SAP_ABA: 700, 701, 702
Full note on SAP: SAP Support Launchpad note 2267789
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
