Medium priority
SAP security note 1515454, "Missing authorization check in SCM-APO-INT-EXT", is a note released on December 14, 2010. Below are the symptom and the SAP recommended solution.
Description
Symptom
Certain functions within SCM-APO-INT-EXT can be accessed without the necessary authorizations. This flaw allows users to escalate their privileges, potentially leading to unauthorized changes in the system behavior.
- Unauthorized access to specific functions in SCM-APO-INT-EXT.
- Potential escalation of user privileges without proper authorization checks.
Solution
Implement the provided correction instructions and import the relevant Support Package appropriate for your system release.
Full note on SAP: SAP Support Launchpad note 1515454
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



