SAP Security Note
HotNews
SAP security note 1120760, "Security note: Missing authorization check for Web services", is a program error note released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
For Web services (service interfaces), the authorization check against the authorization object S_SERVICE is not executed for the provider in the security log (part of the SOAP runtime).
Solution
Implement the correction instructions or import the Support Package.
Reason and prerequisites
This problem is caused by a programming error in the method CL_WS_SECURITY_PROTOCOL->IF_SOAP_SECURITY_HELPER~CHECK_AFTER_DESERIALIZATION.
Prerequisite for the error:
- The system is not an SAP Business ByDesign system, or
- The Web service to be checked was generated using the inside-out approach (not modelled using the ESR outside-in approach), or
- The Web service to be checked is NWA-SI (= http://sap.com/xi/BASIS MBeanAccessInbound).
References
This note refers to
Affected components
- SAP_BASIS 710
Full note on SAP: SAP Support Launchpad note 1120760
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
