Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authorization check for User role in Smart number Generation, SAP security note 1444275

SAP Note 1444275

SAP security note 1444275, "Authorization check for User role in Smart number Generation". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Due to the Smart Number functionality of the Procurement for Public Sector in the Supplier Relationship Management (SAP SRM) solution, it is possible for an anonymous user to change the currently logged-on user’s data and perform unauthorized actions without the knowledge of the logged-in user.

Solution

Implement the attached corrections or apply the appropriate support package. The dynamic transaction calls are now validated using appropriate authority checks to ensure that they can only be executed by authorized users.

Reason and prerequisites

This is a program error caused by missing authorization checks in the smart number generation process. This vulnerability allows malicious users to exploit the smart number generation functionality.

CVSS

Score 0

Affected components

  • SAP SRM 5.0
  • SAP SRM 6.0
  • SAP SRM 7.0
  • SAP SRM 7.01

Full note on SAP: SAP Support Launchpad note 1444275

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More