High priority
SAP security note 1631458, "Missing authorization check in ABAP Debugger", is a program error note released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of the ABAP Debugger to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply the support package mentioned in this note or implement the correction instructions provided.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Affected components
- SAP_BASIS 702
- SAP_BASIS 710 to 730
- SAP_BASIS 731
- SAP_BASIS 800 to 802
Full note on SAP: SAP Support Launchpad note 1631458
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
