SAP Security Note
Medium priority
SAP security note 1943280, "Missing authorization check in XX-CSC-RU-FI", released on 30.03.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of XX-CSC-RU-FI to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement correction instructions attached to this note via SNOTE or install the indicated support package.
Reason and prerequisites
XX-CSC-RU-FI does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
Full note on SAP: SAP Support Launchpad note 1943280
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




