Privilege Escalation via Insufficient Authorization in SAP ABAP Developer Tools
SAP ABAP Developer Tools (Eclipse ADT)
ABAP Developer Tools is the Eclipse-based IDE used by ABAP developers — it should already be restricted to a small developer population. If your landscape gives broader access to ADT, tighten that first. Patch within two weeks.
Vulnerability Detail
Insufficient authorization checks in SAP ABAP Developer Tools (Eclipse ADT) allow a low-privileged attacker to perform unauthorized database operations that should require elevated permissions. Successful exploitation could enable an attacker to read, modify, or delete database records beyond their intended access scope.
Workaround
Review and tighten authorization assignments for ADT users. Restrict ADT access to developer roles only — it should not be accessible to general end users.
Patch Action
Apply SAP Note 3772411. Verify affected versions in the official SAP Note.
Patch Info