Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Authorization for testing, SAP security note 591395

Description

Existing authorizations in roles and profiles that contain the discreet activity ’03’ (“Display”) no longer authorize users to execute development objects.
However, if a full authorization (‘*’) for the activity is contained in authorizations for the S_DEVELOP authorization object, the behavior does not change because the full authorization also includes the new activity ’16’ (“Execute”).
Activity ’16’ (“Execute”) is already defined for the S_DEVELOP authorization object in all releases as of Release 4.0B.
Therefore, you do not need to adjust the authorization object.

Available fix and Supported packages

  • SAP_BASIS | 640 | 640

Affected component

    BC-DWB-TOO
    Workbench Tools: Editors, Painter, Modeler

CVSS

Score: 0

Exploit

Exploit is not available.
For detailed information please contact the mail [email protected].

URL

https://launchpad.support.sap.com/#/notes/591395

TAGS

#AUTHORITY-CHECK

More to explorer