SAP security note 2819170, "[CVE-2019-0383] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)". Below are the symptom and SAP recommended solution.
Description
Symptom
Transaction Management in SAP Treasury and Risk Management does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of missing authorization checks are:
- Abuse functionality restricted to a particular user group
- Unauthorized reading of restricted data
Solution
- Added Authorization Checks: Implemented authorization checks before displaying data for relevant transaction codes.
- Preliminary Correction: Available via Correction Instruction or by implementing the corresponding Support Package.
Reason and prerequisites
Transaction Management lacks authorization checks to verify if an authenticated user is authorized to access certain functions. This oversight may lead to undesired system behavior.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2819170
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
