SAP security note 2000401, "Missing authorization check in IS-A-DP", is a program error note released on 13.01.2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of IS-A-DP to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement support package or correction instructions.
Reason and prerequisites
IS-A-DP does not contain required checks against a positive set of allowed functions (i.e., whitelist) during execution of these functions. This is required to verify that authenticated users are allowed to access these functions. The missing check may result in undesired system behavior.
CVSS
Score 6.0 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P
Affected components
- ECC-DIMP 604
- ECC-DIMP 605
- ECC-DIMP 606
- ECC-DIMP 616
- ECC-DIMP 617
Full note on SAP: SAP Support Launchpad note 2000401
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
