SAP security note 1589367, "Missing authorization check in FI-CA", is a program error note released on 12.07.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of FI-CA to which access should be restricted. This may result in an escalation of privileges.
Solution
Refer to the correction instructions/manual pre-implementation steps provided in the note.
Reason and prerequisites
FI-CA does not contain authorization checks for verifying an authenticated user's authorization to access certain functions. This may result in undesired system behavior.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
Affected components
- FI-CA
Full note on SAP: SAP Support Launchpad note 1589367
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
