SAP security note 2345698, "Missing Authorization check in FI-AA-AA", is a program error note released on 01.03.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
FI-AA-AA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of Missing Authorization checks are:
- Abuse functionality restricted to a particular user group
- Read restricted data
Solution
Implement Support Package or correction instructions.
The correction implements additional checks to restrict the data to be read.
Affected components
- SAP_APPL: 600, 602, 603, 604, 605, 606, 616
- SAP_FIN: 617, 618, 700, 720, 730
- S4CORE: 100, 101
Full note on SAP: SAP Support Launchpad note 2345698
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
