Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0383 Missing Authorization check in SAP Treasury and Risk Management (Transaction Management), SAP security note 2819170

SAP Note 2819170

SAP security note 2819170, "[CVE-2019-0383] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)". Below are the symptom and SAP recommended solution.

Description

Symptom

Transaction Management in SAP Treasury and Risk Management does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Some well-known impacts of missing authorization checks are:

  • Abuse functionality restricted to a particular user group
  • Unauthorized reading of restricted data

Solution

  • Added Authorization Checks: Implemented authorization checks before displaying data for relevant transaction codes.
  • Preliminary Correction: Available via Correction Instruction or by implementing the corresponding Support Package.

Reason and prerequisites

Transaction Management lacks authorization checks to verify if an authenticated user is authorized to access certain functions. This oversight may lead to undesired system behavior.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2819170

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More