SAP Security Note
High priority
SAP security note 1529235, “Missing authorization check in TH_CREATE_FOREIGN_MODE”, is a program error note released on 13.09.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use the functionality of TH_CREATE_FOREIGN_MODE to which access should be restricted. This can potentially result in an escalation of privileges.
Solution
Apply the correction instructions from this note and assign proper authorizations for users allowed to use TH_CREATE_FOREIGN_MODE. The correction includes changes in ABAP and the kernel. Ensure you apply the kernel patch level mentioned in this note. For the ABAP correction, apply the support package specified.
Reason and prerequisites
TH_CREATE_FOREIGN_MODE lacks permission checks for an authenticated user’s authorization to access some of its functionality. This may result in undesired system behavior.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
References
This note refers to
Affected components
- SAP_BASIS 46C to 730
- KERNEL 4.6D to 7.20
Full note on SAP: SAP Support Launchpad note 1529235
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
