Medium priority
SAP security note 1621461, "Missing authorization check in SLL-LEG-FUN", is a program error note released on 12.06.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of SLL-LEG-FUN to which access should be restricted. This may result in an escalation of privileges.
Solution
The related unsecure remote access point was disabled in Release SLL-LEG 10.0. For releases below, implement the relevant Support Package or follow the relevant coding instructions of this note.
Reason and prerequisites
SLL-LEG-FUN does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
Full note on SAP: SAP Support Launchpad note 1621461
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
