SAP security note 1490804, "Missing Authorization Check in Analysis cockpit". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can leverage the functionality of the Analysis Cockpit to access restricted areas. This oversight can lead to an escalation of privileges within the system.
Solution
Implement the corrections provided in the SAP Security Note. The transaction calls have been updated to include appropriate authority checks, ensuring that only authorized users can execute specific transactions.
The solution involves validating transaction calls with proper authority checks, restricting execution to authorized users only.
Reason and prerequisites
The Analysis Cockpit lacks necessary permission checks for validating a user’s authorization to access certain functionalities. This deficiency may result in unintended system behavior.
Affected components
- SAP SRM 5.0
- SAP SRM 6.0
- SAP SRM 7.0
- SAP SRM 7.01
Full note on SAP: SAP Support Launchpad note 1490804
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



