Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in SAP Mobile Defense & Security 1.6, SAP security note 2374749

SAP Note 2374749
SAP Security Note
Medium priority

SAP security note 2374749, "Missing Authorization check in SAP Mobile Defense & Security 1.6", is released on December 13, 2016. Below are the symptom and SAP recommended solution.

ComponentIndustry-Specific Components > Defense Forces and Public Security > MDS Application
PriorityCorrection with medium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released onDecember 13, 2016

Description

Symptom

SAP Mobile Defense & Security 1.6 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Impacts of Missing Authorization Check:

  • Abuse functionality restricted to a particular user group.
  • Read, modify, or delete restricted data.

Solution

The affected function modules have now been enforced to properly check access restrictions. Please implement the correction instructions.

CVSS

Score 6.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Full note on SAP: SAP Support Launchpad note 2374749

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More