SAP security note 2294866, “Missing proper authorization checks in JMS Provider Service”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
Update 31/08/2016: New "Support Packages and Patches" information was added.
JMS Provider Service does not perform necessary authorization checks, resulting in possible escalation of privileges.
Some well-known impacts of missing authorization checks are:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
Update your AS Java to a Support Package (SP) or release where the issue is fixed, i.e., the necessary authorization checks are performed. See the SP Patch Level section for details and available patches.
To adapt the applications after the solution in this note is applied, please refer to the online documentation and the following SCN article.
Reason and prerequisites
Missing proper authorization checks in JMS Provider Service.
CVSS
Score 6.4 Vector: AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
References
Referenced by
- 2679094 – JMSSecurityException occurs due to lack of permissions for the User during JMS message processing
- 2496808 – Issues after SP update of NW (e.g., missing KB update) due to JMS Provider Service authorization check
- 2434638 – Initial data cannot be imported or data migrations display an error after execution
- 2360595 – Extraction requests are not processed
- 2358697 – JMS authorization error after upgrade or support package
- 2516682 – JMS error at RFC and Web service interfaces
Full note on SAP: SAP Support Launchpad note 2294866
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




