Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in RFC, SAP security note 1785761

SAP Note 1785761
SAP Security Note
HotNews

SAP security note 1785761, "Missing authorization check in RFC", is a note released on 12.02.2013. Below are the symptom and the SAP recommended solution.

ComponentBasis Components > Middleware > RFC
PriorityHotNews
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on12.02.2013
LanguageEnglish

Description

Symptom

An authenticated user can use functions of an SAP NetWeaver Server ABAP to which access should be restricted. This may result in an escalation of privileges.

Solution

To address this vulnerability, import the kernel with the patch level specified under "SP Patch Level" in the support package patches section.

Reason and prerequisites

There are insufficient authorization checks for verifying an authenticated user's permissions to access certain functions. This oversight can lead to undesired system behavior.

Affected systems: NetWeaver releases 7.00 and 7.01; Kernel versions 7.20 and 7.21 (downward compatible).

CVSS

Score 9.0 Vector: AV:N/AC:L/AU:S/C:C/I:C/A:C

References

Full note on SAP: SAP Support Launchpad note 1785761

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More