SAP Security Note
Medium priority
SAP security note 2374749, "Missing Authorization check in SAP Mobile Defense & Security 1.6", is released on December 13, 2016. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Mobile Defense & Security 1.6 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Impacts of Missing Authorization Check:
- Abuse functionality restricted to a particular user group.
- Read, modify, or delete restricted data.
Solution
The affected function modules have now been enforced to properly check access restrictions. Please implement the correction instructions.
CVSS
Score 6.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2374749
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
