SAP security note 1638384, "SAML2: privilege escalation", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
Possible privilege escalation using SAML 2.0 authentication.
Solution
Apply the patches provided in this SAP Security Note according to your current version and Service Pack level.
Reason and prerequisites
The implementation of SAML 2.0 contains a vulnerability that could be exploited by an attacker to gain elevated privileges. This vulnerability poses risks such as information disclosure, data tampering, and system unavailability.
Full note on SAP: SAP Support Launchpad note 1638384
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




