Skip links

ABAP web services authorization check does not work, SAP security note 1388864

Description

Authorization check for SOAP web service calls is not working due to a program error. This only effects the start authorization check against authorization object S_SERVICE. It does not effect other authorization checks called by the underlying web service implementation (i.e. a BAPI, a RFC function module or an ESR modeled service).

Available fix and Supported packages

  • SAP_BASIS | 700 | 702
  • SAP_BASIS | 710 | 730
  • SAP_BASIS 710 | SAPKB71009 |
  • SAP_BASIS 711 | SAPKB71104 |
  • SAP_BASIS 700 | SAPKB70021 |
  • SAP_BASIS 701 | SAPKB70106 |
  • SAP_BASIS 720 | SAPKB72002 |

Affected component

    BC-SEC-WSS
    Web Services Security for ABAP

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1388864

TAGS

#

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer

Initiating SAP Penetration Testing

►   Pentest, short for penetration testing, refers to a set of processes that simulate an attacker’s actions to identify security vulnerabilities. Companies