Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Note Check for ‘System -> Status’ (SE80), SAP security note 1085326

Description

This security note has been updated. For more detailed information, see Security Note 1706461.

You are logged on to an SAP system using SAP GUI. You use

    1. the menu:  System -> Status…
    2. in the F1 help (in the modal window):
      a) the F9-button or
      b) ‘Technical Information’ (or ‘Technical info’) from context menu or
      c) ‘Technical Information’ (or ‘Technical info’) button on the F1 Help screen
    3. the button ‘Technical Information’ in the Performance Assistant

to display technical information about the system or the current transaction. By double-clicking, you can display the selected Workbench object, although the authorization for the ABAP Workbench (transaction SE80) was not assigned to your user profile.

Available fix and Supported packages

  • SAP_APPL | 31I | 31I
  • SAP_APPL | 40B | 40B
  • SAP_APPL | 45B | 45B
  • SAP_BASIS | 46B | 46D
  • SAP_BASIS | 610 | 640
  • SAP_BASIS | 700 | 700
  • SAP_BASIS | 710 | 710
  • SAP_APPL 31I | SAPKH31IB9 |
  • SAP_APPL 40B | SAPKH40B89 |
  • SAP_APPL 45B | SAPKH45B67 |
  • SAP_BASIS 610 | SAPKB61048 |
  • SAP_BASIS 46B | SAPKB46B62 |
  • SAP_BASIS 46D | SAPKB46D45 |
  • SAP_BASIS 640 | SAPKB64021 |
  • SAP_BASIS 46C | SAPKB46C55 |
  • SAP_BASIS 620 | SAPKB62063 |
  • SAP_BASIS 710 | SAPKB71004 |
  • SAP_BASIS 700 | SAPKB70014 |
  • SAP_BASIS 710 | SAPKB71006 |

Affected component

    BC-DOC-DTL
    Documentation Tools

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1085326

TAGS

#S_DEVELOP
#16
#SE80
#RDOCFINDER
#search-report
#SE61
#worklist
#RS_ACCESS_PERMISSION
#AUTHORITY_CHECK_TCODE
#RS_TOOL_ACCESS

More to explorer

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.