SAP security note 2906996, "[CVE-2020-6268] Missing authorization check in SAP ERP (Statutory Reporting for Insurance Companies)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Statutory Reporting for Insurance Companies does not execute the required authorization checks for an authenticated user, which may result in an escalation of privileges.
- Unauthorized Function Access: Fraudulent or incorrect use of functions that should be restricted to certain user groups.
- Data Manipulation: Ability to read, modify, or delete data to which access should be restricted.
Solution
Implement the attached correction instructions or import the relevant Support Package. After implementing the corrections, data can be deleted only for company codes where statutory reporting is active.
- Execute Correction Program: use transaction SA38 and execute the program NOTE_2906996. Step 1: perform a test run to identify objects that need updating. Step 2: the program will update the objects in the original language German (DE).
- Manual Message Creation: regardless of your system’s status, message ISSR7 614 is not supported. Create the message manually in transaction SE91 with message class ISSR7, number 614, short text “User &1 does not have sufficient authorization”.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Affected components
- S4CORE: Versions 101 to 104
- EA-FINSERV: Versions 600 to 800
Full note on SAP: SAP Support Launchpad note 2906996
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
