SAP security note 1523808, “Missing authorization check in CATT or eCATT”, released on 17.02.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of CATT or eCATT to which access should be restricted. This may result in an escalation of privileges.
This security note has been updated. For more detailed information, see Security Note 1562119 and Security Note 1575763.
Solution
Implement the correction instructions or import the relevant Support Package.
References
- Update #2 to Security Note 1523808
- Update #1 to Security Note 1523808
- Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- BC-TWB-TST-CAT: Basis Components > Test Workbench > Testing Tools > CATT Computer Aided Test Tool
Full note on SAP: SAP Support Launchpad note 1523808
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
