SAP Security Note
Low priority
SAP security note 2947891, "Missing Authorization check in Disbursement Read API used in Read Disbursement Webservice", is a program error note released on 10.11.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
While reading disbursement data using the Disbursement read webservice, authorization checks are not performed for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of Missing Authorization check are:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
The affected functions have now been enforced to properly check access restrictions. Please implement the correction instructions.
Reason and prerequisites
Authorization checks are missing.
CVSS
Score 3.0 Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 2947891
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




