SAP security note 1498366, “DIMa: Missing Authorization Check, Header Table in ERP”, is a note. Below is the security information published by SAP for this note.
Description
An authenticated user can exploit the Data Integrity Manager (DIMa) functionality without proper authorization checks in ERP, potentially leading to an escalation of privileges. Specifically, the ERP component of DIMa lacks authorization checks that regulate access to its functions, resulting in undesired system behavior. Additionally, there is no existing list of header tables for DIMa objects in ERP.
Solution
1. Import the Specified Support Package:
2. Implement Correction Instructions:
- Follow the detailed correction instructions provided in the note:
References
Full note on SAP: SAP Support Launchpad note 1498366
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




