SAP security note 1499392, "Missing authorization check in CRM Middleware extractor". Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functionality of the CRM Middleware to which access should be restricted. This can potentially result in an escalation of privileges.
Solution
The specified Support Package contains the corrections.
For implementation using transaction SNOTE, note that manual processing steps are required.
See also Notes 1502607, 1501685, and 1498111.
Reason and prerequisites
The CRM Middleware extractor lacks permission checks for an authenticated user’s authorization to access some of its functionality. This may result in undesired system behavior.
References
- 1502607 – Potential disclosure of persisted data
- 1501685 – Table CRMATAB is empty
- 1498111 – No authorization for data selection in initial load
Full note on SAP: SAP Support Launchpad note 1499392
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
