SAP Security Note
High priority
SAP security note 1525896, "Missing Authorization Check in BOD Assignment/SIM Create", is released on 08.02.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can navigate within the transaction BOD assignment and SIM Version Create to other transactions which access should be restricted. This can potentially result in an escalation of privileges.
Solution
Apply Code Correction.
Reason and prerequisites
The transactions for BOD assignment and Simulation Version Create lack permission checks for an authenticated user’s authorization to navigate to further SPP transactions. This may result in undesired system behavior.
Full note on SAP: SAP Support Launchpad note 1525896
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



