Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0243 Missing Authorization check in SAP BW/4HANA, SAP security note 2727623

SAP Note 2727623

SAP security note 2727623, "[CVE-2019-0243] Missing Authorization check in SAP BW/4HANA", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

Under some circumstances, masterdata maintenance in SAP BW/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Some well-known impacts of Missing Authorization check are:

Abuse functionality restricted to a particular user group

Read, modify or delete restricted data

Solution

Implement Support Package 12 for SAP BW/4HANA 1.0 (SAPK-10012INDW4CORE) into your SAP BW/4HANA system.

Alternatively, you can use the correction instructions.

Before you use the correction instructions, make sure that you check SAP Note 1668882 and SAP Note 2248091 for transaction SNOTE.

Reason and prerequisites

The issue is a regression introduced with SAP BW/4HANA 1.0 SP08. Previous SPs are not vulnerable.

CVSS

Score 7.1 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2727623

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More