SAP security note 1839699, "Missing authorization check in CA-MRS", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of CA-MRS to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the attached automatic corrections provided in the security note.
Reason and prerequisites
CA-MRS does not contain authorization checks for verifying an authenticated user's authorization to access certain functions. This lack of checks may result in undesired system behavior and potential escalation of privileges.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Affected components
- MRSS: Versions 700 to 800
- MRSS_NW: Versions 700 to 800
Full note on SAP: SAP Support Launchpad note 1839699
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




