SAP security note 2357856, "Missing Authorization check of Standard Conditions". Below are the symptom, SAP recommended solution, CVSS score and affected software components.
Description
Symptom
Standard Conditions in Account Management do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Impacts of Missing Authorization Check:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
The affected functions have now been enforced to properly check access restrictions. Please implement the correction instructions available for the respective software components.
CVSS
Score 5.4 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected components
- FSAPPL 100
- FSAPPL 200
- FSAPPL 300
- FSAPPL 400
- FSAPPL 500
- BANK-TRBK 40
Full note on SAP: SAP Support Launchpad note 2357856
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
