SAP security note 1591349, "Missing authorization check in BRF". Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of the Business Rule Framework (BRF) to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the correction instructions or import the relevant Support Package.
For the authorization check during the maintenance of BRF objects, you can enter a class for the authorization check for each implementing class. For more information about this, use the field help for the "Authorization Check" field.
Reason and prerequisites
The Business Rule Framework (BRF) does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
References
- 1808402 – Missing authorization check in BC-SRV-BRF
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Full note on SAP: SAP Support Launchpad note 1591349
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
