Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in IS-A-SWP., SAP security note 1881374

SAP Note 1881374
SAP Security Note
High priority

SAP security note 1881374, “Missing authorization check in IS-A-SWP”, released on 12.11.2013. Below are the symptom, SAP recommended solution and the affected software components.

ComponentIndustry-Specific Components > Automotive > Supplier Workplace (IS-A-SWP)
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on12.11.2013

Description

Symptom

An authenticated user can use functions of IS-A-SWP to which access should be restricted. This may result in an escalation of privileges.

Solution

Implement the attached corrections and perform the following manual activities:

  • Go to transaction SE37 -> Function Module ISIDE_SUMJIT_IDOC_READ in CHANGE mode.
  • Navigate to the Attributes tab and change the function module processing type from Remote-enabled Module to Normal Function Module.
  • Save and Activate.

Reason and prerequisites

IS-A-SWP does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may lead to undesired system behavior.

Affected components

  • ECC-DIMP (Versions 600 to 617)

Full note on SAP: SAP Support Launchpad note 1881374

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More