SAP security note 2798133, "[CVE-2019-0325] Missing Authorization Check in SAP ERP HCM". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP ERP HCM Spain does not perform necessary authorization checks for a report that reads payroll data of employees in a certain area. Due to this, under certain conditions, users who previously had authorization to payroll data of an employee, which was later revoked, may retain access to the same data.
This vulnerability allows unauthorized users to access sensitive payroll data, potentially leading to data leakage and compliance issues.
Solution
The affected functions have been updated to properly enforce access restrictions. Please implement the correction instructions.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected components
- SAP_HRCES: Versions 600, 604, 608
Full note on SAP: SAP Support Launchpad note 2798133
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
