SAP Security Note
Low priority
SAP security note 1262016, "Missing authority check in APO transaction.", is a note released on 11.02.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
After implementing Note 1235367, which introduced a new authorization object (C_APO_CVC) to control user rights for CVC maintenance by POS, some authorization checks are still missing. This results in information disclosure due to missing authorization checks in some APO transactions.
Solution
Please apply the attached correction or install the corresponding support package.
Reason and prerequisites
- Prerequisite: Note 1235367 is implemented.
- Issue: Some authorization checks are still missing in APO transactions.
References
- 1306604 – /SAPAPO/MC62 authorization for creating CVCs
- 1235367 – Missing authority check in APO transaction.
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Full note on SAP: SAP Support Launchpad note 1262016
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
