Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authorization check for SRM Analysis Cockpit Tool, SAP security note 1427008

SAP Note 1427008

SAP security note 1427008, "Authorization check for SRM Analysis Cockpit Tool". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A vulnerability exists in the SRM Analysis Cockpit Tool, part of the SAP Supplier Relationship Management (SAP SRM) solution, allowing hackers to access restricted SAP transactions at runtime. This can lead to:

  • Manipulation of Business Logic: Resulting in inconsistent data states.
  • Regulatory Compliance Violations: Unprivileged access to critical business logic may breach compliance requirements.

Solution

Implement the provided corrections to address the vulnerability. The dynamic transaction calls are now validated using appropriate authority checks, ensuring that only authorized users can execute the transactions.

Reason and prerequisites

This issue is caused by missing authorization checks during dynamic calls to transactions from SRM programs. Without proper authorization, malicious users can control these transaction calls, posing significant security risks.

References

Affected components

  • SRM_SERVER: 550 to 550
  • SRM_SERVER: 600 to 600
  • SRM_SERVER: 700 to 700

Full note on SAP: SAP Support Launchpad note 1427008

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More