SAP security note 2392860, "Leveraging privileges by customer transaction code". Below are the symptom and SAP recommended solution.
Description
Symptom
In some SAP standard roles, a transaction code reserved for customers (ZPTTNO_TIME) is used. A malicious user with access to this transaction code can execute unauthorized functionalities, leading to privilege escalation. This requires the user to have permissions to develop and transport custom transactions to the productive system.
Solution
To mitigate this vulnerability, the transaction code ZPTTNO_TIME has been removed from the standard roles:
- SAP_PS_RM_PRO_ADMIN
- SAP_PS_RM_PRO_REVIEWER
Review and adjust the assignments of these roles within your SAP environment. Apply the support packages listed in this SAP Note to ensure the roles are corrected.
CVSS
Score 8.0 / 10 Vector: AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Full note on SAP: SAP Support Launchpad note 2392860
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
