SAP security note 2973100, "Missing Authorization check in Manage Substitutions – Products and Manage Exclusions – Products", is a program error note released on October 13, 2020. Below are the symptom and SAP recommended solution.
Description
Symptom
The Fiori applications Manage Substitutions – Products and Manage Exclusions – Products do not perform necessary authorization checks for authenticated users. This oversight allows users to escalate privileges by:
- Abusing functionality restricted to specific user groups
- Modifying restricted data
Solution
The affected functions have been updated to enforce proper access restrictions. To address this issue, please implement the correction instructions provided in the support package.
Reason and prerequisites
In the mentioned Fiori applications, an authenticated user can modify the status of substitutions and exclusions without proper authorization. This vulnerability can lead to data integrity issues within the product substitution process.
CVSS
Score 3.6 Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2973100
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
