SAP security note 2028559, “RFC Missing authorization check in IS-A (SAP Note 2028559)”, is a program error note released on 11.11.2014. Below is the security information published by SAP for this note.
Description
Symptom
A user might use the Function Modules (FM) SPP02_INVOICE_HEADERDETAIL and SPP02_INVOICE_DETAIL even if they do not have the authority to view the data provided by these FMs.
Reason and prerequisites
There is a missing authority check in the mentioned function modules, allowing unauthorized access to sensitive data.
Solution
Apply the correction instruction provided in the SAP Note to implement the necessary authorization checks.
References
Full note on SAP: SAP Support Launchpad note 2028559
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



