Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6362 Incorrect Authorization in SAP Banking Services, SAP security note 2953212

SAP Note 2953212
Medium priority

SAP security note 2953212, “[CVE-2020-6362] Incorrect Authorization in SAP Banking Services”, is released on 13.10.2020. Below are the symptom and SAP recommended solution.

ComponentFS-BA-SD-PO (Financial Services > Bank Analyzer > Source Data > Primary Objects)
PriorityMedium priority
Released on13.10.2020

Description

Symptom

SAP Banking Services uses an incorrect authorization object in some of its reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability could lead to privilege escalation and violation of segregation of duties, which in turn could lead to service interruptions and system unavailability for the victim and users of the component.

Solution

The incorrect authorization object in vulnerable reports is replaced with the appropriate object. This note’s corrections are delivered with the corresponding support package or by implementing the correction instructions.

Reason and prerequisites

An incorrect authorization object was added via SAP Note 2583046.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

References

This note refers to

Full note on SAP: SAP Support Launchpad note 2953212

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More