SAP security note 2137784, “Missing authorization check in GRC-AUD”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of GRC-AUD to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply this note or ACS1.1 SP06.
Reason and prerequisites
GRC-AUD does not contain authorization checks for checking an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
Full note on SAP: SAP Support Launchpad note 2137784
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
