SAP security note 1562171, "Information disclosure within transportation management". Below are the symptom, the SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability has been identified in the Transportation Management module of SAP, specifically allowing malicious users to disclose sensitive information such as pricing details and change document data. This disclosure can potentially be exploited to target the transportation management system further.
A malicious user can display information relating to sensitive data like pricing information or change document data.
Solution
Implement the correction provided in the correction instructions associated with this SAP Note.
Reason and prerequisites
Information such as pricing details or change document data of settlement documents can be discovered by unauthorized users. This information may be leveraged by malicious actors to further target the transportation management system, potentially leading to unauthorized access or manipulation of transportation data.
CVSS
Score 0
References
- 1569628 – Missing authorization check in FWSD/FSD
- 1522754 – SAP TM 8.0 – collection of notes, pro-active implementation
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- Transportation Management (no software transports) > Forwarding Settlement (TM-FWS)
- Transportation Management (no software transports) > Freight Settlement (TM-FRS)
Full note on SAP: SAP Support Launchpad note 1562171
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




