Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in EA-DFPS, SAP security note 2394024

SAP Note 2394024
SAP Security Note
Medium priority

SAP security note 2394024, "Missing Authorization check in EA-DFPS", is a program error note released on May 9, 2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentIndustry-Specific Components > Defense Forces and Public Security > Materials Management > DFS Logistics Executions (EA-DFPS MM-LE)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released onMay 9, 2017

Description

Symptom

The solution Defense Forces and Public Security (EA-DFPS) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Impacts of Missing Authorization Check:

  • Abuse of functionality restricted to a particular user group
  • Read, modify, or delete restricted data

Multiple RFC-enabled function modules belonging to the IS-DFS-MM component do not contain sufficient authorization checks to verify an authenticated user’s permissions to access certain functions.

Solution

The affected functions have been updated to properly enforce access restrictions. Action Required: Implement the relevant support package or follow the correction instructions available here.

CVSS

Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected components

  • EA-DFPS versions 603 to 618, 800 to 801

Full note on SAP: SAP Support Launchpad note 2394024

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More