Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6233 Missing Authorization Check in SAP S/4 HANA (Financial Products Subledger and Banking Services), SAP security note 2904796

SAP Note 2904796

SAP security note 2904796, “[CVE-2020-6233] Missing Authorization Check in SAP S/4 HANA (Financial Products Subledger and Banking Services)”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP S/4HANA for Financial Products Subledger and Banking Services lacks proper authorization checks, allowing an authenticated user to run an analysis report that leads to system slowdowns.

Impact:

  • Abuse functionality restricted to specific user groups
  • Read, modify, or delete restricted data

Solution

Implement the attached correction or the corresponding service pack.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

References

Affected components

  • FS-BA (Financial Services > Bank Analyzer)
  • FS-FPS (Financial Products Subledger)

Full note on SAP: SAP Support Launchpad note 2904796

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More