Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2494 Missing Authorization check in SAP Customizing Tools, SAP security note 2698996

SAP Note 2698996

SAP security note 2698996, "[CVE-2018-2494] Missing Authorization check in SAP Customizing Tools", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Customizing Tools do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Some well-known impacts of Missing Authorization check are:

  • Abuse functionality restricted to a particular user group
  • Read, modify or delete restricted data

Solution

Where SAP Customizing Tools access RFC destination management, an authorization check for S_RFC_ADM is implemented.

Please implement the Support Package mentioned in this SAP Note or the respective correction instruction.

CVSS

Score 8.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

Affected components

  • SAP_BASIS from 700 to 702
  • SAP_BASIS from 710 to 730
  • SAP_BASIS 731 to 731
  • SAP_BASIS 740 to 740
  • SAP_BASIS from 750 to 753

Full note on SAP: SAP Support Launchpad note 2698996

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More