SAP security note 2063792, "Missing authorization check in LO-AB", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
LO-AB does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This lack of checks may lead to undesired system behavior, allowing users to perform actions beyond their intended permissions.
Solution
The affected function modules in LO-AB do not require RFC enabling. As a corrective measure, this option will be disabled to prevent unauthorized access and ensure that proper authorization checks are enforced.
Reason and prerequisites
The absence of authorization checks in LO-AB means that authenticated users can access and utilize functions without proper authorization verification. This oversight can potentially lead to unauthorized access and privilege escalation within the system.
References
This note refers to
Affected components
- EA-RETAIL (versions 600, 602, 603, 604, 605, 606, 616, 617)
Full note on SAP: SAP Support Launchpad note 2063792
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
