High priority
SAP security note 1776718, "Missing authorization check in password telnet command", is a note released on December 10, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of the password telnet command to which access should be restricted. This may result in an escalation of privileges.
Solution
Update your Java AS to a Support Package (SP) or release where the issue is resolved.
Reason and prerequisites
The password telnet command does not include authorization checks to verify an authenticated user’s permissions for accessing certain functions. This oversight can lead to undesired system behavior and potential privilege escalation.
Full note on SAP: SAP Support Launchpad note 1776718
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




