SAP Security Note
Medium priority
SAP security note 2236289, "Missing authorization check in SMSS_GET_DBCON", is a program error note released on 29.04.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can access a table in function modules SMSS_GET_DBCON, SMSS_MODIFY_CONN, SMSS_WRITE_DBCON, or SMSS_GET_DBO_CONNECTION to which access should be restricted.
Solution
Apply the support package provided in this note or use transaction SNOTE to apply the correction.
CVSS
Score 4.0 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N
Affected components
- SAP_BASIS (700, 701, 702, 710, 711, 730, 731, 740, 750)
Full note on SAP: SAP Support Launchpad note 2236289
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




