Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in DMIS_BSC and DMIS_CNT, SAP security note 2115610

SAP Note 2115610

SAP security note 2115610, “Missing authorization check in DMIS_BSC and DMIS_CNT”, is a note released on 17.04.2015. Below are the symptom, SAP recommended solution and the affected software components.

Released on17.04.2015

Description

Symptom

An authenticated user can use functions of DMIS_CNT and DMIS_BSC to which access should be restricted. This may result in an escalation of privileges.

Solution

Implement the note in all systems where you have installed DMIS_CNT or DMIS_BSC. The correction deactivates an obsolete function.

Reason and prerequisites

DMIS_CNT and DMIS_BSC do not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.

CVSS

Score 0

References

Affected components

  • DMIS_CNT: 2006_1_620, 2006_1_640, 2006_1_700, 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2012_1_620, 2012_1_640, 2012_1_700
  • DMIS_BSC: 2008_1_620, 2008_1_640, 2008_1_700

Full note on SAP: SAP Support Launchpad note 2115610

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More