SAP security note 1720994, “Missing authorization check in ST-PI”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of ST-PI to which access should be restricted. This may result in an escalation of privileges.
Solution
Apply the correction.
Reason and prerequisites
ST-PI does not contain authorization checks for checking an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:N/I:P/A:N
References
This note refers to
Affected components
- ST-PI: 2008_1_620
- ST-PI: 2008_1_640
- ST-PI: 2008_1_700
- ST-PI: 2008_1_710
Full note on SAP: SAP Support Launchpad note 1720994
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
