SAP Security Note
Medium priority
SAP security note 2105620, "Missing authorization check in Calendar Interface", is a program error note released on 12.05.2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of the Calendar Interface to which access should be restricted. This may result in an escalation of privileges.
Solution
Please implement the Support Package mentioned in this SAP Note or follow the correction instructions provided. With the correction RFC enabled, functions of the Calendar Interface will grant access only to data for the current user, and other requests will be refused.
Reason and prerequisites
Calendar Interface does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may lead to undesired system behavior.
Full note on SAP: SAP Support Launchpad note 2105620
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




