SAP security note 2490973, "Missing Authorization Check in SAP SRM". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP SRM does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of missing authorization checks are:
- Abuse of functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
The affected functions have now been enforced to properly check access restrictions. Apply the attached correction instructions or import the corresponding support package.
Reason and prerequisites
The below notes are prerequisites of this note:
- 1882417 – External check for Remote Function Call
- 1988903 – Check whether a function module was called via external RFC
CVSS
Score 6.3/10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
This note refers to
Referenced by
- 2958401 – SRM calls to back-end ECC system don’t return requested data – follow-on note 2490973
Affected components
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
- SAP_APPL 606
- SAP_APPL 616
- SAP_APPL 617
- SAP_APPL 618
Full note on SAP: SAP Support Launchpad note 2490973
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




