SAP security note 1427010, "Unauthorized access to source-of-supply determination prgram". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Due to a vulnerability in the SRM tool that checks if a contract is available for sourcing, it can lead to:
- Manipulation of Business Logic, resulting in inconsistent data states.
- Potential violation of regulatory compliance as this vulnerability allows for unprivileged access to critical business logic.
Solution
Implement the attached corrections. The dynamic transaction calls are now validated using appropriate authority checks, ensuring that only authorized users can execute the transactions.
- Dynamic transaction calls are now validated with proper authority checks.
- Users can only execute transactions if they have the necessary authorizations.
Reason and prerequisites
This is a program error caused by missing authorization checks during dynamic calls to transactions from SRM programs. This vulnerability can be exploited if malicious users can control such transaction calls.
Affected components
- SAP SRM 4.0
- SAP SRM 5.0
- SAP SRM 6.0
- SAP SRM 7.0
Full note on SAP: SAP Support Launchpad note 1427010
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




