SAP security note 2457929, "Missing Authorization check in PY-US", is a note released on 01.10.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
PY-US does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
Additional authorization checks have been incorporated into the affected functions. To implement these changes in your system, you can:
- Apply the Correction Instructions.
- Implement the Support Packages: Refer to the specific support packages listed in the Support Package Section of this SAP Note.
Reason and prerequisites
PY-US lacks sufficient authorization validations to check an authenticated user’s permissions for accessing certain functions. This deficiency may lead to undesired system behavior and potential security breaches.
References
Referenced by
- SAP Note 2587964 – REC: Payroll Reconciliation Splitter background jobs issue
Full note on SAP: SAP Support Launchpad note 2457929
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
