In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://blogs.sap.com/2018/01/09/sap-security-patch-day-january-2018/ | vendor advisory |
https://launchpad.support.sap.com/#/notes/2507934 | permissions required |
http://www.securityfocus.com/bid/102450 | vdb entry third party advisory |