SAP Security Note
Medium priority
SAP security note 1911319, "Missing authorization check in FS-RI", is a note released on 05.02.2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use FS-RI functions to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the authorization checks as outlined in the SAP Note. This involves executing several manual pre-implementation steps using transaction SE11 to create and modify database views and search helps.
Reason and prerequisites
FS-RI does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may result in undesired system behavior.
References
- SAP Note 1716640: Missing authorization check in FS-RI
- SAP Note 1706769: Missing authorization check in FS-RI
Affected components
- FS-RI: 472, 600, 650, 660, 670, 680, 700
Full note on SAP: SAP Support Launchpad note 1911319
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



