Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing proper authorization checks in JMS Provider Service, SAP security note 2294866

SAP Note 2294866

SAP security note 2294866, “Missing proper authorization checks in JMS Provider Service”, is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

Update 31/08/2016: New "Support Packages and Patches" information was added.

JMS Provider Service does not perform necessary authorization checks, resulting in possible escalation of privileges.

Some well-known impacts of missing authorization checks are:

  • Abuse functionality restricted to a particular user group
  • Read, modify, or delete restricted data

Solution

Update your AS Java to a Support Package (SP) or release where the issue is fixed, i.e., the necessary authorization checks are performed. See the SP Patch Level section for details and available patches.

To adapt the applications after the solution in this note is applied, please refer to the online documentation and the following SCN article.

Reason and prerequisites

Missing proper authorization checks in JMS Provider Service.

CVSS

Score 6.4 Vector: AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

References

Full note on SAP: SAP Support Launchpad note 2294866

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More