Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization Check in Security Provider Service, SAP security note 2280932

SAP Note 2280932SAP Security NoteMedium priority

SAP security note 2280932, “Missing Authorization Check in Security Provider Service”, is a program error note released on 10.08.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBC-JAS-SEC-LGN (Basis Components > NetWeaver Application Server Java > Security, User Management > Logon, SSO)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on10.08.2017
LanguageEnglish

Description

Symptom

An authenticated user can use functions of the Security Provider service to which access should be restricted. This may result in an escalation of privileges.

Solution

Update your AS Java to a release or SP where the issue is resolved. See the Validity and SP Patch Level sections of this note.

Reason and prerequisites

The Security Provider service does not check the authorization of an authenticated user for accessing some of the service’s functions. This may result in undesired system behavior.

CVSS

Score 6.7 Vector: AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H

Affected components

  • SERVERCORE 7.31 to 7.31
  • SERVERCORE 7.40 to 7.40

Full note on SAP: SAP Support Launchpad note 2280932

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More