Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized access to source-of-supply determination prgram, SAP security note 1427010

SAP Note 1427010

SAP security note 1427010, "Unauthorized access to source-of-supply determination prgram". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Due to a vulnerability in the SRM tool that checks if a contract is available for sourcing, it can lead to:

  • Manipulation of Business Logic, resulting in inconsistent data states.
  • Potential violation of regulatory compliance as this vulnerability allows for unprivileged access to critical business logic.

Solution

Implement the attached corrections. The dynamic transaction calls are now validated using appropriate authority checks, ensuring that only authorized users can execute the transactions.

  • Dynamic transaction calls are now validated with proper authority checks.
  • Users can only execute transactions if they have the necessary authorizations.

Reason and prerequisites

This is a program error caused by missing authorization checks during dynamic calls to transactions from SRM programs. This vulnerability can be exploited if malicious users can control such transaction calls.

Affected components

  • SAP SRM 4.0
  • SAP SRM 5.0
  • SAP SRM 6.0
  • SAP SRM 7.0

Full note on SAP: SAP Support Launchpad note 1427010

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More