SAP Security Note
High priority
SAP security note 1535611, "Missing authorization check in ST-PI", is a program error note released on 29.07.2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of ST-PI to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the newest ST-PI support package or apply the correction instructions attached to this SAP Note via the SAP Note Assistant.
Reason and prerequisites
ST-PI does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 0
References
- SAP Solution Manager – Basic functions 7.1 SP9
- SAP Solution Manager 7.1 SP8 – Basic functions
- SAP Solution Manager 7.1 SP7 – Basic functions
- SAP Solution Manager 7.1 SP6 – Basic functions
- SAP Solution Manager 7.1 Support Package 05 – Basic Functionality
- SAP Solution Manager: Basic functions 7.1 SP1
Affected components
- ST-PI versions 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710
Full note on SAP: SAP Support Launchpad note 1535611
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



