Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization Checks in SAP Netweaver Data Orchestration Engine, SAP security note 2408892

SAP Note 2408892SAP Security NoteHigh priority

SAP security note 2408892, "Missing Authorization Checks in SAP Netweaver Data Orchestration Engine", is a program error note released on 14.02.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > SAP NetWeaver Mobile Infrastructure > Data Orchestration Engine
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version7
StatusReleased for Customer
Released on14.02.2017
LanguageEnglish

Description

Symptom

Function modules in function groups MMW_CLNT_SYNC_IF_RFC, SMMW_USER_DETAILS, and SMMW_USER_DETAILS do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Some well-known impacts of Missing Authorization check are:

  • Abuse functionality restricted to a particular user group
  • Read, modify, or delete restricted data

Solution

Please implement the assigned corrections mentioned in the note.

Implementation of this note will change the FM of function groups MMW_CLNT_SYNC_IF_RFC, SMMW_USER_DETAILS, and SMMW_USER_DETAILS by including the authorization objects to authenticate user.

Reason and prerequisites

Authorization objects were missing from function groups MMW_CLNT_SYNC_IF_RFC, SMMW_USER_DETAILS, and SMMW_USER_DETAILS.

You are using:

  • NWAs 710: SP16 to SP21
  • NWAs 711: SP12 to SP16
  • NWAs 730: SP12 to SP16
  • SUPDOE Add-On 731: SP01 to SP04

CVSS

Score 8.5

References

Affected components

  • SAP_BASIS: 710 to 711
  • SAP_BASIS: 730 to 730
  • SUPDOE: 731 to 731

Full note on SAP: SAP Support Launchpad note 2408892

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More