Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6199 Missing Authorization check in SAP ERP and S/4 HANA (MENA Certificate Management), SAP security note 2871167

SAP Note 2871167

SAP security note 2871167, “[CVE-2020-6199] Missing Authorization check in SAP ERP and S/4 HANA (MENA Certificate Management)”. Below are the symptom and SAP recommended solution.

Description

Symptom

MENA Certificate Management does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. A user without the appropriate authorization group can maintain company certificates.

Impacts of Missing Authorization Check:

  • Abuse functionality restricted to a particular user group.
  • Read, modify, or delete restricted data.

Solution

SAP recommends installing the solution by applying a Support Package. If an earlier installation is necessary, use the Note Assistant to implement the correction instruction. More information about the Note Assistant can be found on the SAP Service Marketplace.

Reason and prerequisites

The view does not have an authorization check. To address this, an authorization group is being added to enable the right users to access the view.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2871167

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More