Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in ALE Interface, SAP security note 2105634

SAP Note 2105634

SAP security note 2105634, "Missing authorization check in ALE Interface". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An authenticated user can use functions of the ALE Interface to which access should be restricted. This may result in an escalation of privileges.

Solution

Implement the Support Package mentioned in this SAP Note or follow the provided correction instructions. By applying the correction, RFC-enabled functions of the ALE Interface will include authorization checks consistent with those used in the corresponding dialog transactions.

Reason and prerequisites

The ALE Interface does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This omission can lead to undesired system behavior and potential security risks.

References

Affected components

  • SAP_BASIS (700 to 702, 710 to 711, 730 to 731, 740)

Full note on SAP: SAP Support Launchpad note 2105634

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More