SAP security note 2179233, "Missing Authorization Check in LO-MD-BP-CM, LO-MD-BP-VM, FI-AP-AP-N, FI-AR-AR-N". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of LO-MD-BP-CM, LO-MD-BP-VM, FI-AP-AP-N, FI-AR-AR-N to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the attached correction instructions provided in the security note.
Implementing this security note resolves the issue of missing authorization checks but may impact related functionalities if not properly tested.
Reason and prerequisites
These components do not contain authorization checks for verifying an authenticated user’s permissions to access certain functions. This oversight can lead to unintended system behavior and potential security breaches.
Affected components
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
- SAP_APPL 606
- SAP_APPL 616
- SAP_APPL 617
Full note on SAP: SAP Support Launchpad note 2179233
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




