SAP security note 2084143, "Missing authorization check in RFC destination maintenance". Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of RFC connection maintenance to which access should be restricted. This may result in an escalation of privileges.
Solution
Import the appropriate Support Package or apply the correction instructions.
For detailed instructions, refer to the SAP Note 2084143.
Reason and prerequisites
The RFC connection maintenance does not contain authorization checks for verifying an authenticated user's authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 4.9 / 10 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:P
Full note on SAP: SAP Support Launchpad note 2084143
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




