Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security note Missing authorization check for Web services, SAP security note 1120760

Description

For Web services (service interfaces), the authorization check against the authorization object S_SERVICE is not executed for the provider in the security log (part of the SOAP runtime).

Available fix and Supported packages

  • SAP_BASIS | 710 | 710
  • SAP_BASIS 710 | SAPKB71005 |

Affected component

    BC-SEC
    Security – Read KBA 2985997 for subcomponents

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1120760

TAGS

#SOAP
#Simple-Object-Access-Protocol
#security-log
#WSSEC
#S_SERVICE
#RBAM
#AUTHORITY-CHECK
#Web-service

Explore More

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.