SAP security note 2727689, "[CVE-2019-0270] Missing Authorization Check in ABAP Server of SAP NetWeaver", is a note released on 12.03.2019. Below are the symptom and the SAP recommended solution.
Description
Symptom
ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of Missing Authorization Check are:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
The affected functions have been updated to properly check access restrictions. Apply a disp+work package with at least the patch level mentioned in the Support Package & Patches section of this note.
Reason and prerequisites
Using the Dynpro User Interface, a user may enter function codes directly. The processor fails to validate the function correctly, enabling a user to manually enter functions and execute them by bypassing the authorization check. This behavior is due to a program error in the disp+work package of the SAP kernel.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
Full note on SAP: SAP Support Launchpad note 2727689
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
