SAP Security Note
High priority
SAP security note 1688229, "Information disclosure due to missing auth. in EWA functions", is a program error note released on 19.05.2014. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use remote functions of the Service Data framework (Addon ST-PI, SAP Solution Tools Plug-In) to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply Support Package ST-PI 2008_1_* SP08. The solution in this support package consists of the following: in Support Package ST-PI 2008_1_* SP08 the remote functions are either supplied with authorization checks or they are no more remote enabled.
If you are using an old version of the ST-PI AddOn, you can enable the authorization check for remote function calls if not yet done. Users need the following authorizations to access the remote enabled functions:
- Authorization object: S_RFC
- RFC function group: /SDF/EWA
For accessing specific ST-PI Function Modules remotely: since Support Package ST-PI 2008_1_* SP06, function module /SDF/EWA_GET_USER_ACCOUNTS is no longer remote enabled – consider using functionality of the Central User Administration, such as function module SUSR_ZBV_REMOTE_USERS_GET. In Support Package ST-PI 2008_1_* SP06 to SP07, function module /SDF/EWA_GET_PARAMETER_DATA is not remote enabled; see SAP Note 1800234 for more information.
Reason and prerequisites
Several remote enabled functions of the Service Data framework do not contain authorization checks for checking an authenticated user’s authorization to access some of its functions. This may result in information disclosure. The functions are used for remote services such as the EarlyWatch Alert (EWA).
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
References
Full note on SAP: SAP Support Launchpad note 1688229
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



