Medium priority
SAP security note 1661750, "Missing authorization check in LOD-ESO-AS", is a program error note released on 12.06.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of LOD-ESO-AS to which access should be restricted. This may result in an escalation of privileges.
Without proper authorization checks, unauthorized users may gain access to restricted functions within LOD-ESO-AS, potentially leading to escalation of privileges and compromising system security.
Solution
Fixes have been developed and released in:
- Version 5.0 J
- Version 5.1 Patch 10
- All Version 7.0 SP and patch releases
Update to the appropriate Release/Patch version to mitigate this risk.
Reason and prerequisites
LOD-ESO-AS does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
Affected components
- LOD-ESO-AS (OnDemand > Sourcing OnDemand > Accounts & Security)
Full note on SAP: SAP Support Launchpad note 1661750
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



