SAP security note 2043119, “Missing Authorization Check for User Exits in Liquidity Planner”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can utilize functions (exits) in the Liquidity Planner to which access should be restricted. This oversight may result in undesired system behavior, potentially compromising the security and integrity of financial data.
Without proper authorization checks, unauthorized users might access or manipulate critical functions within the Liquidity Planner, leading to data inconsistencies and potential financial discrepancies.
Solution
To address this issue, you have two options:
- Implement Manual Steps: follow the detailed correction instructions provided in the SAP Security Note to manually create the necessary tables, transactions, and messages to enforce authorization checks.
- Import the Relevant Support Package: apply the appropriate support packages listed in the note to automatically incorporate the required authorization checks.
Affected components
- SAP_APPL: Versions 600 to 617
- SAP_FIN: Version 617 and 700
- EA-FINSERV: Versions 600 to 617
Full note on SAP: SAP Support Launchpad note 2043119
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
