SAP security note 1531142, "Improved authorization check in function module RZL_SUBMIT", is released on July 12, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
The function module RZL_SUBMIT contains insufficient authorization checks. This module is utilized in system administration functions, such as executing system programs on the application server (e.g., in transaction RZ03). Currently, only administrators can execute this function, with authorization checks implemented within the function module itself.
Solution
Enhance the authorization checks to restrict the use of the function exclusively to administrators (authorization object S_RZL_ADM). To address this issue, import the relevant support package or implement the correction instructions provided in this note.
Full note on SAP: SAP Support Launchpad note 1531142
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




