SAP security note 1478420, "FPE2M: Missing Authorization Check". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use the functionality of transaction FPE2M (Mass Document Change) to which access should be restricted. This can potentially result in an escalation of privileges.
Solution
Implement the corrections in accordance with the correction instructions provided in the SAP Note or import the relevant Support Package.
References
- Syntax error when implementing a security note (1624291)
- FPE2M: Missing function module FKK_LOCKS_CHECK_AUTHORITY (1511853)
- FPE2M: Locks not being changed (1662259)
Affected components
- Industry-Specific Components > Public Sector Solutions > Public Sector Contract Accounting (IS-PS-CA)
- Industry-Specific Components > Media > Contract Accounts Receivable and Payable (IS-M-CA)
- Industry-Specific Component Telecommunications > Contract Accounting (IS-T-CA)
- Industry-Specific Components > Utilities > Contract Accounts Receivable and Payable (IS-U-CA)
- Financial Services > Collections and Disbursements (FS-CD)
- Financial Accounting > Non-industry specific contract accounts receivable, payable (FI-CAX)
Full note on SAP: SAP Support Launchpad note 1478420
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
