SAP Security Note
Medium priority
SAP security note 2177403, "Missing authorization check in IS-A-VMS", is a program error note released on 03.02.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of IS-A-VMS to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the attached correction instructions.
Reason and prerequisites
IS-A-VMS does not contain authorization checks for checking an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
Affected components
- DIMP: 471
- ISPSADIN: 10A
- ECC-DIMP: 500, 600, 602, 603, 604, 605, 606, 616, 617
- DI: 46C2
Full note on SAP: SAP Support Launchpad note 2177403
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




