Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6311 Improper Authorization Checks in Banking services from SAP Bank Analyzer and SAP S/4HANA Financial Products, SAP security note 2951325

SAP Note 2951325
SAP Security Note
Medium priority

SAP security note 2951325, “[CVE-2020-6311] Improper Authorization Checks in Banking Services”, is a program error note released on 27.10.2020. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFinancial Services > Bank Analyzer > Processes & Methods > Smart Accounting for Financial Instruments (FS-BA-PM-SFA)
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version7
StatusReleased for Customer
Released on27.10.2020
LanguageEnglish

Description

Symptom

SAP Security Note 2951325 addresses a vulnerability (CVE-2020-6311) related to improper authorization checks in banking services from SAP Bank Analyzer and SAP S/4HANA Financial Products. This issue may allow privilege escalation and expose restricted banking data, posing significant data privacy and protection risks.

Solution

To resolve this vulnerability, follow these steps:

  • Execute transaction code SU21.
  • Search for the authorization object F_BABR_BAS.
  • Edit this authorization object and add the new activity ’01’.
  • Save the changes.
  • After making this change, verify if existing roles need adjustment using transaction code PFCG, as the new activity may require updates to role definitions.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected components

  • FSAPPL: Version 500
  • S4FPSL: Version 100

Full note on SAP: SAP Support Launchpad note 2951325

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More