SAP Security Note
Medium priority
SAP security note 2443232, "Missing Authorization check in /FSGLO/CN_API_LSAP_SET", was released on 17.03.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
/FSGLO/CN_API_LSAP_SET does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Impacts:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
Implement the note via the transaction SNOTE to resolve the issue mentioned under Symptom.
Reason and prerequisites
Authorization error.
Full note on SAP: SAP Support Launchpad note 2443232
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
