SAP security note 2013080, “Missing authorization check in standalone POD in Manufacturing Execution”, is a note. Below is the security information published by SAP for this note.
Description
Symptom
A non-authenticated user can use functions of standalone POD to which access should be restricted. This may result in an escalation of privileges.
This issue only exists when the POD is being opened via a standalone URL. After logging out of such POD by clicking the logout link the user session might sometimes stay open. The next user working on that PC will be able to open the POD under the credentials of the first user without having to log in. Clicking the logout link twice, instead of once, always closes the session.
Solution
Code corrections have been implemented within the WPMF framework to ensure that logout occurs every time the Logout icon is clicked in the POD.
Full note on SAP: SAP Support Launchpad note 2013080
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
