Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2454 Missing Authorization check in SAP Enterprise Financial Services, SAP security note 2645133

SAP Note 2645133

SAP security note 2645133, "[CVE-2018-2454] Missing Authorization check in SAP Enterprise Financial Services", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

SAP Enterprise Financial Services does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • Abuse functionality restricted to a particular user group
  • Read, modify, or delete restricted data

Solution

The affected functions have now been enforced to properly check access restrictions. Please implement the attached correction instruction using transaction SNOTE.

CVSS

Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References

This note refers to

  • SAP Note 1513313 – RFBKPRENOTEARCDISPLAY short dump DBIF_RSQL_INVALID_RSQL (Component: IS-B-BCA-AM)
  • SAP Note 2588167 – Report FIPR_ATTRTREE_CHECK: Incomplete Report Attributes (Component: IS-B-BCA)
  • SAP Note 2644818 – BKK_ARC_PRENOTE_DISPLAY: E131(BKK_PRENOTE) "Invalid parameter while reading from archive" (Component: IS-B-BCA-AM)

Full note on SAP: SAP Support Launchpad note 2645133

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More