SAP Security Note
Medium priority
SAP security note 1486533, “Missing authorization check in RFC call”, is a note released on December 14, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can utilize functionality of an RFC call that should have restricted access. This can potentially lead to an escalation of privileges.
Solution
Implement the correction instructions provided in this note to resolve the issue.
Reason and prerequisites
The RFC call lacks proper permission checks for an authenticated user’s authorization to access certain functionalities. This may result in undesired system behavior.
Full note on SAP: SAP Support Launchpad note 1486533
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
