Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security fix for event determination program, SAP security note 1443934

SAP Note 1443934

SAP security note 1443934, "Security fix for event determination program", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A vulnerability exists in the SRM tool for determining event customizing within the SAP Supplier Relationship Management (SAP SRM) solution. This flaw allows potential attackers to access restricted SAP transactions at runtime, which can lead to:

1. Manipulation of Business Logic: Causing inconsistent data states.

2. Violation of Regulatory Compliance: Granting unprivileged access to critical business logic.

Solution

Implement the provided corrections to address the vulnerability by replacing the generic conditions used in the customizing access program.

References

Affected components

  • SAP SRM 6.0
  • SAP SRM 7.0

Full note on SAP: SAP Support Launchpad note 1443934

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More