SAP Security Note
High priority
SAP security note 1488453, "Missing Authorization Check in Mapping Function Module", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use the functionality of condition cross-client customizing download from ERP to CRM to which access should be restricted. A table name is used as an input without further checking in the program.
Solution
An authority check has been added to this function module so that only clients with cross-client customizing maintenance authorization and users with condition generation authorization (object /SAPCND/CO activity 64) can execute this program.
Reason and prerequisites
Condition cross-client customizing download lacks permission checks for an authenticated user’s authorization to access some of its functionality. This may result in undesired system behavior.
CVSS
Score 0
Affected components
- BBPCRM 400 to 701
Full note on SAP: SAP Support Launchpad note 1488453
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



