SAP security note 1638049, “Authorization issue in portal SAP connector”. Below are the symptom and SAP recommended solution.
Description
Symptom
A user can get a connection of a different user to the same RFC destination. As a result, a user can see content without appropriate authorization.
Solution
Install the provided patch. You can download it here.
Reason and prerequisites
You are running SAP NetWeaver 7.3 or higher.
Full note on SAP: SAP Support Launchpad note 1638049
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



