Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

RFC Missing authorization check in IS-A, SAP security note 2028559

SAP Note 2028559SAP Security NoteMedium priority

SAP security note 2028559, “RFC Missing authorization check in IS-A (SAP Note 2028559)”, is a program error note released on 11.11.2014. Below is the security information published by SAP for this note.

ComponentIndustry-Specific Components > Automotive
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on11.11.2014
LanguageEnglish

Description

Symptom

A user might use the Function Modules (FM) SPP02_INVOICE_HEADERDETAIL and SPP02_INVOICE_DETAIL even if they do not have the authority to view the data provided by these FMs.

Reason and prerequisites

There is a missing authority check in the mentioned function modules, allowing unauthorized access to sensitive data.

Solution

Apply the correction instruction provided in the SAP Note to implement the necessary authorization checks.

References

Full note on SAP: SAP Support Launchpad note 2028559

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More