SAP security note 1411818, "Handling Authorization concerns due to Note1030838 & 1381945". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
At present, if View Maintenance Authorization Enhancement has been implemented in a system, any application table that has a maintenance dialog can lead to improper information disclosure. The Note 1030838 (Valid from release 610 up to 700) or Note 1381945 (Valid for release 701 up to 710) should have been implemented in the system for this symptom to occur.
Solution
Please implement the code changes as outlined in the note.
Reason and prerequisites
An error in the code was introduced by Note 1030838 (Valid from release 610 up to 700) or Note 1381945 (Valid for release 701 up to 710) provided to handle authorization enhancement for customizing/configuration tables.
CVSS
Score 0
References
- 1543826 – Handling authorization concerns due to Note1030838 & 1381945
- 1394963 – Authorization check S_TABU_DIS for Customizing tables
- 1381945 – SM30: View Maintenance Authorization Enhancement
- 1276656 – SM30: Authorization Check – Delivery class ‘A’ tables
- 1240557 – View Maintenance Authorization: Customizing category check
- 1030838 – SM30: View Maintenance Authorization Enhancement
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- SAP_BASIS: 620 to 640
- SAP_BASIS: 700 to 702
- SAP_BASIS: 710 to 720
Full note on SAP: SAP Support Launchpad note 1411818
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
