SAP security note 2280932, “Missing Authorization Check in Security Provider Service”, is a program error note released on 10.08.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of the Security Provider service to which access should be restricted. This may result in an escalation of privileges.
Solution
Update your AS Java to a release or SP where the issue is resolved. See the Validity and SP Patch Level sections of this note.
Reason and prerequisites
The Security Provider service does not check the authorization of an authenticated user for accessing some of the service’s functions. This may result in undesired system behavior.
CVSS
Score 6.7 Vector: AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
Affected components
- SERVERCORE 7.31 to 7.31
- SERVERCORE 7.40 to 7.40
Full note on SAP: SAP Support Launchpad note 2280932
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




