SAP security note 1562782, "Missing authorization check in GRC-SPC", is a security note. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of GRC-SPC to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply the attached correction instructions or the related support package.
Reason and prerequisites
GRC-SPC does not contain authorization checks for verifying an authenticated user’s permissions to access certain functions. This oversight may lead to undesired system behavior.
References
Full note on SAP: SAP Support Launchpad note 1562782
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
