SAP security note 1499051, "DBACockpit: Weak authorization checks in SQL Command Editor". Below are the symptom and SAP recommended solution.
Description
Symptom
The detailed authorization check is not implemented in the SQL Command Editor, potentially allowing unauthorized access to certain tables or views.
Solution
Implement the provided corrections from the security note to enforce enhanced authorization checks in the SQL Command Editor.
Reason and prerequisites
The system currently lacks detailed authorization checks in the SQL Command Editor, which this note aims to correct.
CVSS
Score 2.1 Vector: AV:N/AC:H/AU:S/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1499051
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
