SAP Security Note
HotNews
SAP security note 1614719, "Missing authorization check in ETM planning", is a program error note released on October 11, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of ETM planning to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the attached correction instruction provided in the note.
Reason and prerequisites
ETM planning does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may lead to undesired system behavior.
References
- SAP Note 1624291 – Syntax error when implementing a security note
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- ECC-DIMP 500
- ECC-DIMP 600
- ECC-DIMP 602
- ECC-DIMP 603
- ECC-DIMP 604
- ECC-DIMP 605
- ECC-DIMP 606
Full note on SAP: SAP Support Launchpad note 1614719
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



