Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

DBACockpit Weak authorization checks in SQL Command Editor, SAP security note 1499051

SAP Note 1499051

SAP security note 1499051, "DBACockpit: Weak authorization checks in SQL Command Editor". Below are the symptom and SAP recommended solution.

Description

Symptom

The detailed authorization check is not implemented in the SQL Command Editor, potentially allowing unauthorized access to certain tables or views.

Solution

Implement the provided corrections from the security note to enforce enhanced authorization checks in the SQL Command Editor.

Reason and prerequisites

The system currently lacks detailed authorization checks in the SQL Command Editor, which this note aims to correct.

CVSS

Score 2.1 Vector: AV:N/AC:H/AU:S/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 1499051

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More