SAP security note 1910914, “Missing authorization check in BC-DOC-HLP”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of BC-DOC-HLP to which access should be restricted. This may result in an escalation of privileges.
Solution
Use the Note Assistant to implement the corrections or import the relevant Support Package.
Before implementing this Note, create the export parameter EV_NO_EDIT (type CHAR1, short text: “Editing not allowed”) for the function module DOCU_AUTHORITYLOAD, and activate it.
Reason and prerequisites
BC-DOC-HLP does not contain authorization checks for verifying an authenticated user’s permissions to access certain functions. This can lead to undesired system behavior and potential privilege escalation.
CVSS
Score 4.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N
Affected components
- SAP_BASIS versions 46B to 46D, 620 to 740
Full note on SAP: SAP Support Launchpad note 1910914
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



