SAP Security Note
HotNews
SAP security note 1363631, “BADI BUPA_F4_AUGRP does not filter BP’s in search”, released on 17.02.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The search help feature displayed Business Partner details even when the user lacked the necessary authorization. This allows users without sufficient permissions to view Business Partner data through the search help, which is unintended behavior.
Solution
Implement the solution provided in this SAP Note to ensure that Business Partners are correctly filtered based on user authorizations.
Reason and prerequisites
The issue occurs if the authorization role does not include the B_BUPA_GRP object. The code responsible for filtering Business Partners in the search results relies on this authorization object. If it’s missing, the BADI implementation BUPA_F4_AUGRP fails to filter the Business Partners appropriately.
CVSS
Score 0
References
Affected components
- SAP_ABA: versions 640, 700 to 702, and 710 to 711
Full note on SAP: SAP Support Launchpad note 1363631
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



