PT-2013-24: Concealing User Authority in SAP NetWeaver
Version: 7.31 and earlier
Severity level: Medium
Impact: Concealing User Authority
Access Vector: Remote
Base Score: 4.6
CVE: not assigned
SAP NetWeaver is a special software solution by SAP that is a basis for all SAP Business Suite applications.
The specialists of the Positive Research center have detected "Concealing User Authority" vulnerability in SAP NetWeaver.
No matter how much authority the user '............' has, it is not reflected in report RSUSR002.
How to fix
Update your software up to the latest version
20.03.2013 - Vendor gets vulnerability details
10.06.2013 - Vendor releases fixed version and details
13.09.2013 - Public disclosure
The vulnerability was detected by Dmitry Gutsko, Positive Research Center (Positive Technologies Company)
Reports on the vulnerabilities previously discovered by Positive Research: