Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check two NWA plug-ins, SAP security note 1430587

SAP Note 1430587

SAP security note 1430587, “Missing authorization check two NWA plug-ins”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An authenticated read-only user can use the full functionality of the "Destinations" and the "Session monitoring" NWA plug-ins although no modifications should be possible in these plug-ins for read-only users. This may result in an escalation of privileges.

Solution

Upgrade your SAP J2EE Engine to:

  • SAP J2EE Engine 701 – SP07
  • SAP J2EE Engine 702 – SP04

Reason and prerequisites

The "Destinations" and "Session monitoring" NWA plug-ins do not correctly maintain the checks of the authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.

CVSS

Score 0

Affected components

  • LM-TOOLS: From 7.01 To 7.02

Full note on SAP: SAP Support Launchpad note 1430587

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More