SAP security note 2904796, “[CVE-2020-6233] Missing Authorization Check in SAP S/4 HANA (Financial Products Subledger and Banking Services)”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP S/4HANA for Financial Products Subledger and Banking Services lacks proper authorization checks, allowing an authenticated user to run an analysis report that leads to system slowdowns.
Impact:
- Abuse functionality restricted to specific user groups
- Read, modify, or delete restricted data
Solution
Implement the attached correction or the corresponding service pack.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
References
This note refers to
- SAP Note 1833817 – RDL: improve the RDL archiving performance
- SAP Note 1866880 – RDL: SQL exception during archiving write step
- SAP Note 1870501 – RDL new results ignored by analysis of a delete arch. scen.
- SAP Note 1954034 – RDL: long runtime during archiving write step
- SAP Note 2304130 – RDL: RGV and SV archiving is incomplete
- SAP Note 2517505 – RDL: dump SAPSQL_PARSE_ERROR during archiving engine analysis
- SAP Note 2507605 – AR_ENGINE Dump DBSQL_INVALID_CURSOR (Enhancement of SAPNote 235291)
- SAP Note 2540246 – RDL : dump during the archiving write step
- SAP Note 2619106 – Dump CL_AR_LOG->ADD – OBJREF_NOT_ASSIGNE
- SAP Note 2772058 – Archiving dumps for result types with result category HKFLG (2 Dimensional Versioning and flat persistency)
- SAP Note 2897957 – Result category HWFLG: Incorrect generation of function modules
Affected components
- FS-BA (Financial Services > Bank Analyzer)
- FS-FPS (Financial Products Subledger)
Full note on SAP: SAP Support Launchpad note 2904796
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
