SAP security note 1430587, “Missing authorization check two NWA plug-ins”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated read-only user can use the full functionality of the "Destinations" and the "Session monitoring" NWA plug-ins although no modifications should be possible in these plug-ins for read-only users. This may result in an escalation of privileges.
Solution
Upgrade your SAP J2EE Engine to:
- SAP J2EE Engine 701 – SP07
- SAP J2EE Engine 702 – SP04
Reason and prerequisites
The "Destinations" and "Session monitoring" NWA plug-ins do not correctly maintain the checks of the authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 0
Affected components
- LM-TOOLS: From 7.01 To 7.02
Full note on SAP: SAP Support Launchpad note 1430587
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




