SAP security note 1520043, "RFC Call cat_r2_tab_res Without Authorization". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note has been updated. For more detailed information, see Security Note 1585311.
An authenticated user can use functionality of the function module cat_r2_tab_res to which access should be restricted. This can potentially result in an escalation of privileges.
Solution
Import the correction instructions or the appropriate support package.
Reason and prerequisites
The function module cat_r2_tab_res lacks permission checks for an authenticated user’s authorization to access some of its functionality. This may result in undesired system behavior.
References
- Security Note 1585311 – Update #1 to Security Note 1520043
- Security Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- Basis Components > Test Workbench > Testing Tools > CATT Computer Aided Test Tool (BC-TWB-TST-CAT)
- SAP_APPL 31I to 31I
- SAP_APPL 40A to 40B
- SAP_APPL 45A to 45B
- SAP_BASIS 46A to 46D, 610 to 640, 700 to 702, 710 to 730
Full note on SAP: SAP Support Launchpad note 1520043
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
