Description
Missing authorizations are a common problem, especially for security frameworks using a pro-grammatic approach to specifying authorizations. The classic authority-check statement is an example for that. Security critical resources require a successful authorization check before they can be accessed. If this check is missing, the currently logged in user obtains elevated privileges.
An unauthorized user can run a the report /SAPAPO/RSP_PLAN_LOG_DELETE and delete planning and scheduling logs for resources
Available fix and Supported packages
- SCM | 410 | 410
- SCM | 500 | 500
- SCM | 510 | 510
- SCM | 700 | 700
- SCM | 701 | 701
- SCM 410 | SAPKY41020 |
- SCM 700 | SAPKY70006 |
- SCM 500 | SAPKY50018 |
- SCM 510 | SAPKY51014 |
- SCM 701 | SAPKY70101 |
Affected component
- SCM-APO-PPS-RSP
Reservation Planning
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1430941