SAP Security Note
Low priority
SAP security note 1470094, "Authorization check in report H99_B2AFILE missing", is a program error note released on 10.08.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
There is a security vulnerability in the report H99_B2AFILE where certain functions can be executed without the required authorizations. This omission can lead to privilege escalation, allowing an attacker to read and write data on the application server and potentially alter system behavior.
An attacker exploiting this vulnerability may gain unauthorized access to sensitive data or manipulate application server files, compromising the integrity and confidentiality of the SAP system.
Solution
Follow the instructions in SAP Note 1448318 to apply the necessary HR Support Package.
Ensure that users executing the report have the following authorizations:
- P_B2A (Authorization object)
- B2A_ACTIO: R – Reorganize notifications
If the report H99_B2AFILE is not required in your integrated systems (e.g., FI & HCM), consider deleting it to eliminate the risk.
References
- 1448318 – IMG: Supplements for absences and remuneration statement
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- SAP_HR: 46C
- SAP_HRCDE: 470, 500, 600, 604
Full note on SAP: SAP Support Launchpad note 1470094
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
