Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized access to view procurement document, SAP security note 1427009

SAP Note 1427009

SAP security note 1427009, "Unauthorized access to view procurement document". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A vulnerability in the SRM tool which displays the procurement document details, can lead to any or all of the following:

  • Manipulation of Business Logic, resulting in inconsistent data states
  • May lead to violation of regulatory compliance as this vulnerability allows for unprivileged access to critical business logic.

Solution

Please implement the attached corrections.

Solution details: the dynamic transaction calls are now validated using appropriate authority checks so that they can now be called only by users authorized to execute the transactions.

Reason and prerequisites

This is a program error. This error is caused due to missing authorization checks during dynamic calls to transactions from SRM programs. This can be dangerous if such a transaction call can be controlled by malicious users.

CVSS

Score 0

References

Affected components

  • SAP SRM 4.0
  • SAP SRM 5.0
  • SAP SRM 6.0
  • SAP SRM 7.0
  • SRM_SERVER from 500 to 500
  • SRM_SERVER from 550 to 550
  • SRM_SERVER from 600 to 600
  • SRM_SERVER from 700 to 700

Full note on SAP: SAP Support Launchpad note 1427009

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More