SAP Security Note
Medium priority
SAP security note 2297003, "Missing Authorization check in EC-PCA-IS", is a program error note released on 06.06.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
EC-PCA-IS does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of missing authorization checks are:
- Abuse functionality restricted to a particular user group
- Read restricted data
Solution
Implement the relevant Support Package or follow the provided correction instructions.
Reason and prerequisites
Please note that this correction is only relevant if you are using HANA as a primary or secondary database. Additionally, the correction is restricted to the line item browser accelerator for EC-PCA. If you are not using this specific line item browser, you do not need to apply this correction.
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2297003
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
