SAP security note 1942511, "Missing authorization check in Incident Management". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Incident search dialog does not contain proper authorization checks for validating an authenticated user’s authorization to access some of the incident information. This may result in undesired revealing of confidential information. An authenticated user who does not have the access level of "Confidential Access" or "Person Involved Access" may still execute specific searches to find a participant in an incident.
Solution
You can address this issue by applying the relevant Support Packages or implementing the correction instructions.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
References
This note refers to
- SAP Note 1945292 – Unexpected error while working under user role with restricted authorizations.
Affected components
- EHSM 300
- EHSM 400
Full note on SAP: SAP Support Launchpad note 1942511
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




