SAP Security Note
Medium priority
SAP security note 2394024, "Missing Authorization check in EA-DFPS", is a program error note released on May 9, 2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The solution Defense Forces and Public Security (EA-DFPS) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Impacts of Missing Authorization Check:
- Abuse of functionality restricted to a particular user group
- Read, modify, or delete restricted data
Multiple RFC-enabled function modules belonging to the IS-DFS-MM component do not contain sufficient authorization checks to verify an authenticated user’s permissions to access certain functions.
Solution
The affected functions have been updated to properly enforce access restrictions. Action Required: Implement the relevant support package or follow the correction instructions available here.
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected components
- EA-DFPS versions 603 to 618, 800 to 801
Full note on SAP: SAP Support Launchpad note 2394024
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
