Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization Check in a BTE application, SAP security note 1466156

SAP Note 1466156SAP Security NoteMedium priority

SAP security note 1466156, "Missing Authorization Check in a BTE application", is a program error note released on 08.06.2010. Below are the symptom, SAP recommended solution and affected software components.

ComponentCA-GTF-TS-BRHF
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on08.06.2010
LanguageEnglish

Description

Symptom

An authenticated user can use functionality of a BTE application to which access should be restricted. This can potentially result in an escalation of privileges. In this case, a deactivation of an application is possible without the corresponding authorization for activating it.

Solution

Please implement the attached correction instruction in your system.

Reason and prerequisites

A BTE application lacks permission checks for an authenticated user's authorization to access some of its functionality. This may result in undesired system behavior.

References

Affected components

  • SAP_ABA 620
  • SAP_ABA 640
  • SAP_ABA 700 to 702
  • SAP_ABA 710 to 711

Full note on SAP: SAP Support Launchpad note 1466156

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More