SAP security note 1783807, “Missing authorization checks in CA-CL”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of CA-CL to which access should be restricted. This may result in an escalation of privileges.
CA-CL does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This oversight can lead to unauthorized access and undesired system behavior.
Solution
Implement the correction instructions provided in the SAP Security Note. Follow these steps to apply the necessary authorization checks.
Reason and prerequisites
The absence of proper authorization checks in CA-CL allows users to perform actions beyond their intended permissions, potentially compromising system security.
References
Affected components
- SAP_APPL: 31I, 40B, 45B, 46B, 46C
- SAP_ABA: 620, 640, 700-730, 731
Full note on SAP: SAP Support Launchpad note 1783807
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
