SAP security note 2055180, “Missing whitelist check in CA-DMS”, is a note released on November 13, 2014. Below is the security information published by SAP for this note.
Description
Symptom
An authenticated user can use functions of CA-DMS (old component LO-PDM) to which access should be restricted. This may result in an escalation of privileges.
Reason and prerequisites
CA-DMS does not contain required checks against a positive set of allowed functions (i.e., whitelist) during the execution of these functions. This is necessary to verify that authenticated users are permitted to access these functions. The missing check may result in undesired system behavior.
Solution
Implement a support package or follow the provided correction instructions.
## Affected Software Components
## References
- Download for SNOTE
- PDF Version
## Additional Information
- Release Status: Released for Customer
- Released On: November 13, 2014
- Priority: Correction with medium priority
Credits to https://redrays.io for support provided in compiling this information.
Full note on SAP: SAP Support Launchpad note 2055180
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



