SAP Security Note
SAP security note 2079818, "Missing authorization check in SRM-EBP-ADM-XBP", is a note released on 15.10.2014. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of SRM-EBP-ADM-XBP to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the included correction.
Reason and prerequisites
SRM-EBP-ADM-XBP does not contain authorization checks for verifying an authenticated user's authorization to access certain functions. This may result in undesired system behavior.
Full note on SAP: SAP Support Launchpad note 2079818
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
