SAP Security Note
High priority
SAP security note 1525296, “Missing authorization checks in /SAPAPO/START”, is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use the function scope of the transactions called in the report /SAPAPO/START to which access should be restricted. This may lead to an escalation of authorizations.
Solution
Implement the correction instructions relevant for your release or import the relevant Support Package.
Reason and prerequisites
Authorization checks that can be used to verify the authorization of the authenticated user for access to functions within the function scope are missing. This may lead to unwanted system behavior.
- Prerequisite: Note 1429098 is required for the implementation of this note.
References
Affected components
- SAP_APO: 30A, 310
- SCM: 400, 410, 500, 510
Full note on SAP: SAP Support Launchpad note 1525296
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
