SAP Security Note
Medium priority
SAP security note 2951325, “[CVE-2020-6311] Improper Authorization Checks in Banking Services”, is a program error note released on 27.10.2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 2951325 addresses a vulnerability (CVE-2020-6311) related to improper authorization checks in banking services from SAP Bank Analyzer and SAP S/4HANA Financial Products. This issue may allow privilege escalation and expose restricted banking data, posing significant data privacy and protection risks.
Solution
To resolve this vulnerability, follow these steps:
- Execute transaction code SU21.
- Search for the authorization object F_BABR_BAS.
- Edit this authorization object and add the new activity ’01’.
- Save the changes.
- After making this change, verify if existing roles need adjustment using transaction code PFCG, as the new activity may require updates to role definitions.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected components
- FSAPPL: Version 500
- S4FPSL: Version 100
Full note on SAP: SAP Support Launchpad note 2951325
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
