SAP security note 2045395, “Missing whitelist check in CA-DMS”, is a note released on 13.11.2014. Below is the security information published by SAP for this note.
Description
Symptom
An authenticated user can use functions of CA-DMS (old component LO-PDM) to which access should be restricted. This may result in an escalation of privileges.
Reason and prerequisites
CA-DMS does not contain required checks against a positive set of allowed functions (i.e., whitelist) during the execution of these functions. This is necessary to verify that authenticated users are permitted to access these functions. The absence of this check may lead to undesired system behavior.
Solution
Implement the provided support package or follow the correction instructions detailed below.
Affected components
- SAP_APPL versions 600 to 617
Full note on SAP: SAP Support Launchpad note 2045395
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



