SAP Security Note
Medium priority
SAP security note 2201916, "Missing authorization check in XX-CSC-IN-FI", released on April 21, 2016. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of XX-CSC-IN-FI to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply the provided code corrections to ensure proper authorization checks are in place.
Reason and prerequisites
XX-CSC-IN-FI does not contain authorization checks for verifying an authenticated user’s permissions to access certain functions. This oversight can lead to undesired system behavior and potential security vulnerabilities.
Full note on SAP: SAP Support Launchpad note 2201916
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




