SAP Security Note
High priority
SAP security note 1860308, "Missing authorization check in CA-GTF", is a program error note released on August 13, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of CA-GTF-MDC to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the provided support package or follow the correction instructions.
Reason and prerequisites
CA-GTF-MDC does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 4.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:P
References
This note refers to
Referenced by
Full note on SAP: SAP Support Launchpad note 1860308
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



