SAP security note 1686917, "Missing authorization check in engineering change management", released on April 10, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can access functions within Engineering Change Management that should be restricted, potentially leading to an escalation of privileges. The absence of proper authorization checks allows users to perform unauthorized actions, resulting in undesired system behavior.
Solution
To mitigate this vulnerability, implement the correction instructions provided in the security note.
References
Affected components
- SAP_ABA 620
- SAP_ABA 640
- SAP_ABA 700 to 702
- SAP_ABA 710 to 711
- SAP_ABA 730 to 731
Full note on SAP: SAP Support Launchpad note 1686917
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
