SAP security note 2753629, "[CVE-2019-0279] Missing Authorization check for ABAP INST function module". Below are the symptom and the SAP recommended solution.
Description
Symptom
ABAP BASIS function modules covered in the correction instruction do not perform necessary authorization checks in all circumstances for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of Missing Authorization check are:
- Abuse functionality restricted to a particular user group
- Modify or delete specific data
Solution
Enforced privilege requirements for the function modules covered in the correction instruction:
- The authority check will be performed in any case.
- A user that does not have the S_RFC_ADM role will get an authorization failure.
This vulnerability has also been fixed in the cloud environment. Hot fixes have been released as part of S/4HANA Cloud 1902.
This is fixed with the Support Packages and Patches of the Software Components referenced by this note in the section ‘SP Patch Level’.
Reason and prerequisites
Any ABAP system fitting to the related support package and release level.
CVSS
Score 5.5 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
Full note on SAP: SAP Support Launchpad note 2753629
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
