SAP security note 2516864, "Missing Authorization Check in QM", is a program error note released on February 2, 2018. Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.
Description
Symptom
The Quality Management (QM) module does not perform the required authorization checks for an authenticated user, which may result in privilege escalation. The known effects of the missing authorization check include:
- Inappropriate usage of functions restricted to certain user groups.
- Reading, modification, or deletion of data to which access should be restricted.
Solution
Implement the correction instructions provided in this SAP Note to address the missing authorization checks.
Reason and prerequisites
Insufficient authorization checks have led to this vulnerability.
Affected components
- SAP_APPL: 46C, 470, 500, 600, 602, 603, 604, 605, 606, 616, 617, 618
- SAPSCORE: 110
- S4CORE: 100, 101, 102
Full note on SAP: SAP Support Launchpad note 2516864
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




