Medium priority
SAP security note 2944188, "[CVE-2020-6316] Missing Authorization Check in SAP ERP and SAP S/4 HANA", is a program error note released on 09.03.2021. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Update 9th March 2021: this note has been re-released with updated ‘Correction instruction’ information.
SAP ERP and SAP S/4 HANA allow an authenticated user to view cost records for objects to which they do not have authorization in PS reporting.
An authenticated user with limited permissions can access sensitive cost records, potentially leading to unauthorized disclosure of financial information.
Solution
Implement the code changes via transaction SNOTE. After applying the note, users will only see objects within a project that they are authorized to access.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected components
- SAP_APPL: 600 to 618
- S4CORE: 100 to 104
Full note on SAP: SAP Support Launchpad note 2944188
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
