SAP security note 2103389, "Missing authorization check in BC-VMC", is a note released on October 13, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can access BC-VMC functions without proper authorization checks. This vulnerability may lead to an escalation of privileges within the system.
Solution
- Apply Kernel Patch. Apply a suitable kernel patch (disp+work) for your release that meets or exceeds the patch level specified in the Support Packages and Patches documentation. Refer to SAP Note 19466 for detailed instructions on downloading and installing the patch.
- Activate the Patch. Enable the patch in your system by setting the parameter
vmcj/property/Admin_Security_Active = onin the system profile.
Reason and prerequisites
BC-VMC lacks the necessary authorization checks to verify an authenticated user's permissions for accessing certain functions. This omission can result in unintended system behavior and potential security breaches.
Full note on SAP: SAP Support Launchpad note 2103389
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
