Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

DBACockpit Authorization check for SQL Command Editor, SAP security note 1665921

SAP Note 1665921
SAP Security Note
High priority

SAP security note 1665921, "DBACockpit: Authorization check for SQL Command Editor", is a program error note released on June 12, 2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Computer Center Management System (CCMS) > CCMS Monitoring & Alerting > Database Monitors for Oracle
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onJune 12, 2012
LanguageEnglish

Description

Symptom

This security note addresses an authorization check issue in the DBA Cockpit for Oracle systems. Specifically, it corrects the authorization process for the SQL Command Editor.

Before applying this note, users with sufficient authorization encountered incorrect behavior in the SQL Command Editor.

Solution

After implementing this note:

  • Local system (permitted): display of Oracle views owned by SYS; display of table contents (as in SE16), controlled via the authorization object S_TABU_DIS (users must have roles with ACTVT = 03 and DICBERCLS = *).
  • Remote system (permitted): display of Oracle views owned by SYS.
  • Remote system (restricted): display of table contents is not permitted.

Reason and prerequisites

The issue was caused by a program error affecting authorization checks.

References

Affected components

  • SAP_BASIS 701
  • SAP_BASIS 702
  • SAP_BASIS 711
  • SAP_BASIS 730
  • SAP_BASIS 731

Full note on SAP: SAP Support Launchpad note 1665921

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More