SAP security note 1831053, "Missing Authorization Check in CM Services (BC-CTS-CMS)", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can exploit missing authorization checks in CM Services (BC-CTS-CMS), potentially leading to privilege escalation.
Solution
Apply the following Support Package Stacks to mitigate the issue:
- LM-TOOLS 7.01 SP14
- LM-TOOLS 7.02 SP14
- LM-CTS 7.20 SP09 Patch 1
- LM-CTS 7.30 SP10
- LM-CTS 7.31 SP08
- LM-CTS 7.40 SP03
CVSS
Score 5.5 Vector: AV:N/AC:L/AU:S/C:P/I:P/A:N
References
Affected components
- LM-TOOLS: Releases 7.01 to 7.02
- LM-CTS: Releases 7.20, 7.30, 7.31, 7.40
Full note on SAP: SAP Support Launchpad note 1831053
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




