SAP Security Note
High priority
SAP security note 1881374, “Missing authorization check in IS-A-SWP”, released on 12.11.2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of IS-A-SWP to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the attached corrections and perform the following manual activities:
- Go to transaction SE37 -> Function Module ISIDE_SUMJIT_IDOC_READ in CHANGE mode.
- Navigate to the Attributes tab and change the function module processing type from Remote-enabled Module to Normal Function Module.
- Save and Activate.
Reason and prerequisites
IS-A-SWP does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may lead to undesired system behavior.
Affected components
- ECC-DIMP (Versions 600 to 617)
Full note on SAP: SAP Support Launchpad note 1881374
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
