SAP Security Note
High priority
SAP security note 2065073, “Missing authorization check in System Trace”, released on January 13, 2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of transaction ST01 (System Trace) to which access should be restricted. This may result in an escalation of privileges.
Solution
To address this issue, install the corresponding Support Package or implement the provided Correction Instructions.
The solution checks for S_ADMI_FCD authorization with the value “ST0R”.
Reason and prerequisites
Transaction ST01 does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This lack of checks may lead to undesired system behavior and potential privilege escalation.
CVSS
Score 4.9 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:P
Affected components
- SAP_BASIS versions 700 to 702
- SAP_BASIS versions 710 to 730
- SAP_BASIS version 731
- SAP_BASIS version 740
Full note on SAP: SAP Support Launchpad note 2065073
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




