SAP security note 1663799, "Missing authorization check in NWA", is a note released on September 5, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note has been updated. For more detailed information, see Security Note 1743359.
An authenticated user can use functions of NWA to which access should be restricted. This may result in an escalation of privileges.
Solution
Update your AS Java to a Support Package (SP) or release where the issue is fixed. See the Support Package Patch section below for details and available patches.
Reason and prerequisites
NWA does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
References
Affected components
- LMNWAUIFRMRK 7.20
- LMNWAUIFRMRK 7.30
- LMNWAUIFRMRK 7.31
Full note on SAP: SAP Support Launchpad note 1663799
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



