Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0384 Missing Authorization check in SAP Treasury and Risk Management (Transaction Management), SAP security note 2828981

SAP Note 2828981

SAP security note 2828981, "[CVE-2019-0384] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Transaction Management in SAP Treasury and Risk Management (TRM) does not perform necessary authorization checks for functionalities that require user identity.

Missing authorization checks can lead to:

  • Unauthorized reading, modification, or deletion of sensitive information
  • Access to administrative or other privileged functionalities

Solution

New authorization checks have been implemented. You can apply a preliminary correction via Correction Instructions or by installing the corresponding Support Package.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected components

  • S4CORE 101
  • S4CORE 102
  • S4CORE 103
  • S4CORE 104
  • EA-FINSERV 600
  • EA-FINSERV 603
  • EA-FINSERV 604
  • EA-FINSERV 605
  • EA-FINSERV 606
  • EA-FINSERV 616
  • EA-FINSERV 617
  • EA-FINSERV 618
  • EA-FINSERV 800

Full note on SAP: SAP Support Launchpad note 2828981

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More