Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

/SAPAPO/MC62 authorization for creating CVCs, SAP security note 1306604

SAP Note 1306604
SAP Security Note
High priority

SAP security note 1306604, “/SAPAPO/MC62 authorization for creating CVCs”, is a note released on 09.10.2009. Below are the symptom, reason and prerequisites, SAP recommended solution, CVSS score, related references and the affected software components.

ComponentSupply Chain Management > Advanced Planning and Optimization > Demand Planning > Basic Functions
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on09.10.2009

Description

Symptom

Authorization object C_APO_CVC (introduced by Note 1235367) is used to limit rights for CVC maintenance.

A user has authorization to create CVCs for a POS A, but not for POS B.

On the first screen of /SAPAPO/MC62, the user enters POS A, then on the next screen, using the Get Variant button, selects a variant for POS B. Authorization is not checked again, allowing the user to create CVCs for POS B.

Solution

Apply the attached correction or install the corresponding support package.

Reason and prerequisites

Reason: Program error. When the POS is read from a variant, the authorization object C_APO_CVC is not checked.

Prerequisites: Notes 1235367 and 1262016 must be applied.

CVSS

Score 0

References

Affected components

  • SCM 410
  • SCM 500
  • SCM 510
  • SCM 700

Full note on SAP: SAP Support Launchpad note 1306604

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More