Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Switchable Authorization Checks in Central Finance Infrastructure Components, SAP security note 2638217

SAP Note 2638217
SAP Security Note
Low priority

SAP security note 2638217, "Switchable Authorization Checks in Central Finance Infrastructure Components", is a note. Below are the symptom, CVSS score and SAP recommended solution.

ComponentFinancial Accounting > Central Finance > Infrastructure, Tools, Mapping Framework (FI-CF-INF)
PriorityLow priority
TypeSAP Security Note
Version3 (Updated on 28.05.2024)
StatusReleased for Customer

Description

Symptom

The application does not perform sufficient authorization checks, potentially allowing unauthorized access to certain functionalities within Central Finance.

Solution

New switchable authorization checks have been implemented and are delivered inactive to maintain compatibility with your current processes. These checks can be activated manually via transaction SACF as described in SAP Note 2608312.

FINS_CFIN_TARGET – Central Finance Authority Check – Target Part

This scenario includes new authorization checks for various Central Finance transactions, reports, and APIs in areas such as:

  • Mapping tool
  • Key mapping audit log
  • Third-party interface
  • Project system replication
  • Comparison reports
  • Deletion report

CVSS

Score 3.9 Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

Full note on SAP: SAP Support Launchpad note 2638217

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More