SAP security note 2408892, "Missing Authorization Checks in SAP Netweaver Data Orchestration Engine", is a program error note released on 14.02.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Function modules in function groups MMW_CLNT_SYNC_IF_RFC, SMMW_USER_DETAILS, and SMMW_USER_DETAILS do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of Missing Authorization check are:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
Please implement the assigned corrections mentioned in the note.
Implementation of this note will change the FM of function groups MMW_CLNT_SYNC_IF_RFC, SMMW_USER_DETAILS, and SMMW_USER_DETAILS by including the authorization objects to authenticate user.
Reason and prerequisites
Authorization objects were missing from function groups MMW_CLNT_SYNC_IF_RFC, SMMW_USER_DETAILS, and SMMW_USER_DETAILS.
You are using:
- NWAs 710: SP16 to SP21
- NWAs 711: SP12 to SP16
- NWAs 730: SP12 to SP16
- SUPDOE Add-On 731: SP01 to SP04
CVSS
Score 8.5
References
Affected components
- SAP_BASIS: 710 to 711
- SAP_BASIS: 730 to 730
- SUPDOE: 731 to 731
Full note on SAP: SAP Support Launchpad note 2408892
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
