Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in CA-CL, SAP security note 2029526

SAP Note 2029526
SAP Security Note
Medium priority

SAP security note 2029526, "Missing authorization check in CA-CL", is a note released on 11.11.2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCross-Application Components > Classification (CA-CL)
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released on11.11.2014

Description

Symptom

An authenticated user can use functions of CA-CL to which access should be restricted. This may result in an escalation of privileges.

Solution

Implement correction instructions.

Reason and prerequisites

CA-CL does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may lead to undesired system behavior.

References

Affected components

  • SAP_APPL 600
  • SAP_APPL 602
  • SAP_APPL 603
  • SAP_APPL 604
  • SAP_APPL 605
  • SAP_APPL 606
  • SAP_APPL 616
  • SAP_APPL 617

Full note on SAP: SAP Support Launchpad note 2029526

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More