Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

ChaRM Missing authorization check in SV-SMG-CM, SAP security note 2053197

SAP Note 2053197
SAP Security Note
Medium priority

SAP security note 2053197, "ChaRM: Missing authorization check in SV-SMG-CM", is a note released on 17.06.2015. Below are the symptom, SAP recommended solution and the affected software components.

ComponentService > SAP Solution Manager > Change Request Management (SV-SMG-CM)
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on17.06.2015

Description

Symptom

An authenticated user can use functions of SV-SMG-CM to which access should be restricted. This may result in an escalation of privileges.

Solution

Implement the attached corrections using the Note Assistant (SNOTE) on the managed system.

Reason and prerequisites

SV-SMG-CM does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may lead to undesired system behavior.

References

  • 1111600 – Target groups containing dots are incorrectly handled
  • 1999112 – ChaRM: performance improvement for ChaRM reporting data fetch jobs
  • 1354430 – Read CTS project status switches for non ABAP systems
  • 1843985 – ChaRM: incorrect transport request type is read from /TMWFLOW/REP_DATA_READ
  • 1957755 – ChaRM: import error after project is closed and reopened
  • 1166457 – ChaRM: New Collecting data method for reporting
  • 1269192 – ChaRM: Collecting New Data in Asynch and Synch Mode
  • 1635449 – ChaRM Report: data extracting job performance issue

Affected components

  • SAP_BASIS 700 – 702
  • SAP_BASIS 710 – 730
  • SAP_BASIS 731
  • SAP_BASIS 740

Full note on SAP: SAP Support Launchpad note 2053197

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More