Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in report RKEDELE1, SAP security note 1944155

SAP Note 1944155
SAP Security Note
Medium priority

SAP security note 1944155, "Missing authorization check in report RKEDELE1", is a program error note released on 01.08.2018. Below are the symptom and SAP recommended solution.

ComponentControlling > Profitability Analysis (CO-PA)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on01.08.2018
LanguageEnglish (Master Language: German)

Description

Symptom

An authenticated user can execute the report RKEDELE1, to which access should be restricted.

Solution

Implement the correction instructions or import the Support Package relevant to your release.

The report RKEDELE1 is checked against the authorization object K_KEA_TC with the activity 02 (Change).

Reason and prerequisites

The report RKEDELE1 does not contain authorization checks for validating an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.

Full note on SAP: SAP Support Launchpad note 1944155

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More