SAP security note 2841874, “[CVE-2020-6204] Missing Authorization Check in SAP Treasury and Risk Management (Transaction Management)”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Treasury and Risk Management (Transaction Management) allows an attacker with basic authorization to access product type information they would otherwise not have access to. The vulnerable selection query returns more records than it should, thus leading to an information disclosure. However, if an attacker tries to directly access details of an individual contract, the correct authorization will be checked and granted/denied accordingly.
Solution
Apply the preliminary correction via the Correction Instructions or implement the corresponding Support Package. After this note, authorization object T_DEAL_PD will be checked. If you have properly set up the authorization according to the proposal, you won’t be affected.
Reason and prerequisites
Transaction Management does not contain checks for an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected components
- S4CORE
- EA-FINSERV
Full note on SAP: SAP Support Launchpad note 2841874
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
