Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0367 Missing Authorization Check in B2B Content Manager of B2B Add-On for SAP NetWeaver Process Integration, SAP security note 2805777

SAP Note 2805777

SAP security note 2805777, "[CVE-2019-0367] Missing Authorization Check in B2B Content Manager of B2B Add-On for SAP NetWeaver Process Integration". Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Process Integration (PI) > Connectivity > B2B add-on (business-to-business) > Integration Cockpit

Description

Symptom

The B2B Content Manager of B2B Add-on for SAP NetWeaver Process Integration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Some well-known impacts of a missing authorization check are:

  • Abuse functionality restricted to a particular user group
  • Read, modify, or delete restricted data

Solution

Apply the latest patch version for the component indicated in the "Support Packages & Patches" section of this SAP Security Note.

Reason and prerequisites

EDI Content Manager does not perform authorization checks properly for all B2B standards.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2805777

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More