SAP Security Note
High priority
SAP security note 1306604, “/SAPAPO/MC62 authorization for creating CVCs”, is a note released on 09.10.2009. Below are the symptom, reason and prerequisites, SAP recommended solution, CVSS score, related references and the affected software components.
Description
Symptom
Authorization object C_APO_CVC (introduced by Note 1235367) is used to limit rights for CVC maintenance.
A user has authorization to create CVCs for a POS A, but not for POS B.
On the first screen of /SAPAPO/MC62, the user enters POS A, then on the next screen, using the Get Variant button, selects a variant for POS B. Authorization is not checked again, allowing the user to create CVCs for POS B.
Solution
Apply the attached correction or install the corresponding support package.
Reason and prerequisites
Reason: Program error. When the POS is read from a variant, the authorization object C_APO_CVC is not checked.
Prerequisites: Notes 1235367 and 1262016 must be applied.
CVSS
Score 0
References
- 1262016 – Missing authority check in APO transaction
- 1235367 – Missing authority check in APO transaction
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- SCM 410
- SCM 500
- SCM 510
- SCM 700
Full note on SAP: SAP Support Launchpad note 1306604
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
