Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6306 Missing Authorization check in SAP Leasing, SAP security note 2865348

SAP Note 2865348

SAP security note 2865348, "[CVE-2020-6306] Missing Authorization check in SAP Leasing". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The authorization check is not performed when transaction FIEH01 is executed from the customer end, potentially allowing unauthorized access.

Solution

To mitigate this issue, additional switchable authorization checks have been implemented and are delivered inactive by default. Follow these steps to resolve the vulnerability:

Activate Switchable Authorization Checks: Follow the correction instructions to manually activate the additional authorization checks via transaction SACF.

  • Start transaction SACF.
  • Enter “FI_LA” as the scenario name and select “Scenario Definition”.
  • Double-click on the FI_LA entry, then click “Change”.
  • Use the “New” button to add the following authorization objects: F_BKPF_BED, F_BKPF_BUK, F_KNA1_BED, F_KNA1_BUK.
  • Select all new entries and set their status to “Check active without restrictions”.
  • Save your changes.

CVSS

Score 2.7 (Low) Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

References

Affected components

  • SAP_APPL 618
  • EA-APPL versions 600 through 617

Full note on SAP: SAP Support Launchpad note 2865348

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More