SAP security note 2381388, "Missing Authorization check in SAP ERP Materials Management". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
In the DFPS stock transfer process, the system does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of a missing authorization check are:
- Abuse of functionalities restricted to a particular user group
- Read, modify, or delete restricted data
Solution
The affected functions have now been enforced to properly check access restrictions. Please implement the correction instructions.
CVSS
Score 4.3/10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected components
- EA-DFPS 605
- EA-DFPS 606
- EA-DFPS 616
- EA-DFS 617
- EA-DFPS 618
- EA-DFPS 800
- EA-DFPS 801
Full note on SAP: SAP Support Launchpad note 2381388
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




