Medium priority
SAP security note 2452697, "Missing Authorization check in RDL", is a program error note released on 07.04.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The RDL component lacks the necessary authorization checks, which allows authenticated users to escalate their privileges. This can lead to:
- Abuse of functionality restricted to specific user groups
- Unauthorized reading, modification, or deletion of restricted data
Solution
The solution involves adding the required authority checks in the read/write APIs of the RDL component to ensure proper authorization is enforced.
References
This note refers to
- SAP Note 2294432 – Error when writing 2-dimensional key date results SmartAFI
- SAP Note 2333318 – Saving Smart AFI documents in chunks
- SAP Note 2380959 – Shortdump while selecting posting documents
- SAP Note 2415698 – Selection in RDL table for target values
Affected components
- FSAPPL (Version 500)
Full note on SAP: SAP Support Launchpad note 2452697
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
