SAP Security Note
Low priority
SAP security note 1466479, "Potential information disclosure relating to Account Plan", released on 10.08.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can discover information relating to planning profile groups. This information could be used to allow malicious users to specialize their attacks against Account Planning.
Solution
Please follow the manual steps provided below:
- Go to transaction se11.
- In the field "Database table", enter CACP_PLANGRPPROF.
- Click on the button "Display".
- From the menu "Utilities", select "Assign Authorization Group".
- From the menu "Table View", select "Display -> Change".
- In the column "Authorization" associated with table CACP_PLANGRPPROF, change the value from &NC& to CRMC.
- Save.
Reason and prerequisites
Information such as the planning profile group composition can be discovered. This information can potentially be used by a malicious user to further target Account Planning.
Full note on SAP: SAP Support Launchpad note 1466479
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
