SAP security note 2828981, "[CVE-2019-0384] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Transaction Management in SAP Treasury and Risk Management (TRM) does not perform necessary authorization checks for functionalities that require user identity.
Missing authorization checks can lead to:
- Unauthorized reading, modification, or deletion of sensitive information
- Access to administrative or other privileged functionalities
Solution
New authorization checks have been implemented. You can apply a preliminary correction via Correction Instructions or by installing the corresponding Support Package.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected components
- S4CORE 101
- S4CORE 102
- S4CORE 103
- S4CORE 104
- EA-FINSERV 600
- EA-FINSERV 603
- EA-FINSERV 604
- EA-FINSERV 605
- EA-FINSERV 606
- EA-FINSERV 616
- EA-FINSERV 617
- EA-FINSERV 618
- EA-FINSERV 800
Full note on SAP: SAP Support Launchpad note 2828981
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
