High priority
SAP security note 1945300, "Missing whitelist check in QM-IM", was released on February 11, 2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of QM-IM to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the available support package or apply the correction instructions provided in this note.
- Navigate to Quality Management in your SAP system.
- Go to Quality Inspection > Subsystems > Process quality inspections using QM-IDI-interface.
- Define the Subsystem Connection for QM-IDI Interface.
- Double-click on the subsystem (QDR system) and maintain the allowed function modules in the field
V_QISUB-NOTIFYFUNCTION.
Reason and prerequisites
QM-IM does not contain required checks against a positive set of allowed functions (i.e., a whitelist) during the execution of these functions. This is necessary to verify that authenticated users are permitted to access these functions. The missing check may result in undesired system behavior.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Affected components
- SAP_APPL (46B to 617)
Full note on SAP: SAP Support Launchpad note 1945300
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
