SAP security note 1479762, "Missing authority check in SAP_RSADMIN_MAINTAIN". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functionality of SAP_RSADMIN_MAINTAIN to which access should be restricted. This can potentially result in an escalation of privileges.
Solution
An authority check 'S_TABU_DIS' for the table RSADMIN has been added accordingly to the authority checks for customizing transactions. Apply the corresponding note or Support Package.
Reason and prerequisites
SAP_RSADMIN_MAINTAIN lacks permission checks for an authenticated user’s authorization to access some of its functionality. This may result in undesired system behavior.
References
Affected components
- SAP_BW: 30B, 310, 350, 700 to 702, 711, 730
- SAP_BW_VIRTUAL_COMP: 30B, 701
Full note on SAP: SAP Support Launchpad note 1479762
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




