Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0270 Missing Authorization check in ABAP Server of SAP NetWeaver, SAP security note 2727689

SAP Note 2727689SAP Security NoteMedium priority

SAP security note 2727689, "[CVE-2019-0270] Missing Authorization Check in ABAP Server of SAP NetWeaver", is a note released on 12.03.2019. Below are the symptom and the SAP recommended solution.

ComponentBasis Components > ABAP Runtime Environment – ABAP Language Issues Only > Dynpro and CUA engine
PriorityMedium priority
TypeSAP Security Note
StatusReleased for Customer
Released on12.03.2019

Description

Symptom

ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Some well-known impacts of Missing Authorization Check are:

  • Abuse functionality restricted to a particular user group
  • Read, modify, or delete restricted data

Solution

The affected functions have been updated to properly check access restrictions. Apply a disp+work package with at least the patch level mentioned in the Support Package & Patches section of this note.

Reason and prerequisites

Using the Dynpro User Interface, a user may enter function codes directly. The processor fails to validate the function correctly, enabling a user to manually enter functions and execute them by bypassing the authorization check. This behavior is due to a program error in the disp+work package of the SAP kernel.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References

Full note on SAP: SAP Support Launchpad note 2727689

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More