Medium priority
SAP security note 1915920, "Missing authorization check in FS-RI", is a note released on May 13, 2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can utilize functions within FS-RI that should be restricted. This vulnerability may result in an escalation of privileges, allowing unauthorized actions within the system.
Solution
The security note implements necessary authorization checks to ensure that only users with the appropriate permissions can access sensitive functions within FS-RI. Applying this note mitigates the risk of privilege escalation by enforcing strict access controls.
Reason and prerequisites
The FS-RI component lacks proper authorization checks for certain functions. This omission can lead to undesired system behavior, as unauthorized users might gain access to sensitive operations without appropriate permissions.
References
- SAP Note 1551781 – CORR: Participation and gross participation in account search
- SAP Note 1634701 – CORR: Incorrect account search in Risk Manager
- SAP Note 1258637 – CORR: FS-RI non-life account search – external references
Affected components
- Financial Services > Re-Insurance > Accounting > Risk Manager (FS-RI-AC-RM)
- Software versions: 600, 650, 660, 670, 680
Full note on SAP: SAP Support Launchpad note 1915920
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



