Search This Blog

Tuesday, August 23, 2011

SAP Note 1142067 - Missing authorization check for hidden functions

Symptom

You can use authorization objects to display or hide functions in applications. However, you can still execute these functions by manipulating the URL on a Business Server Page (BSP). An additional authorization check before execution is missing.


Other terms
Forceful browsing


Reason and Prerequisites
This problem is caused by a design error.


Solution
Import the Support Package specified in the attachment or implement the correction instructions.



Affected Releases
Software
Component
Release
From
Release
To
Release
And
subsequent
ERECRUIT
300
300
300
 
ERECRUIT
600
600
600
 
ERECRUIT
603
603
603
 
ERECRUIT
604
604
604
 


Visit https://service.sap.com/sap/support/notes/1142067 for Correction delivered in Support Package and Corrections Instructions

No comments:

Post a Comment