SAP Security Note
High priority
SAP security note 1665921, "DBACockpit: Authorization check for SQL Command Editor", is a program error note released on June 12, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses an authorization check issue in the DBA Cockpit for Oracle systems. Specifically, it corrects the authorization process for the SQL Command Editor.
Before applying this note, users with sufficient authorization encountered incorrect behavior in the SQL Command Editor.
Solution
After implementing this note:
- Local system (permitted): display of Oracle views owned by SYS; display of table contents (as in SE16), controlled via the authorization object S_TABU_DIS (users must have roles with ACTVT = 03 and DICBERCLS = *).
- Remote system (permitted): display of Oracle views owned by SYS.
- Remote system (restricted): display of table contents is not permitted.
Reason and prerequisites
The issue was caused by a program error affecting authorization checks.
References
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
- SAP Note 1776682 – DBACockpit: SQL Command Editor authorization check
- SAP Note 1727951
Affected components
- SAP_BASIS 701
- SAP_BASIS 702
- SAP_BASIS 711
- SAP_BASIS 730
- SAP_BASIS 731
Full note on SAP: SAP Support Launchpad note 1665921
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
