SAP security note 1812645, “Missing authorization check in JIT”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can utilize JIT functions without appropriate authorization, resulting in possible escalation of privileges.
Solution
Implement the corrections provided in the SAP Security Note to enforce proper authorization checks within the JIT component.
Reason and prerequisites
The JIT component does not perform necessary authorization checks to verify if an authenticated user has the permissions required to access certain functions. This lack of verification can lead to unintended system behavior and potential security breaches.
CVSS
Score 4.9 Vector: AV:N/AC:M/AU:S/C:N/I:P/A:P
References
- SAP Note 2171754 – JIT: Error message JIT00 114 does not exist in the release 617
- SAP Note 2149322 – Issues implementing the note in release EHP 617
Affected components
- ECC-DIMP: 500 to 617
Full note on SAP: SAP Support Launchpad note 1812645
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
