SAP security note 2137898, “Missing authorization check in SD-SLS”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of SD-SLS to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the following coding corrections.
Reason and prerequisites
SD-SLS does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
Affected components
- SAP_APPL 500 to 617
Full note on SAP: SAP Support Launchpad note 2137898
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
