Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-26832 Missing Authorization check in SAP NetWeaver AS ABAP and SAP S4 HANA (SAP Landscape Transformation), SAP security note 2993132

SAP Note 2993132

SAP security note 2993132, "[CVE-2020-26832] Missing Authorization check in SAP NetWeaver AS ABAP and SAP S4 HANA (SAP Landscape Transformation)". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Landscape Transformation contains a vulnerability that allows a high-privileged user to execute an RFC function module without proper authorization checks. This flaw can enable attackers to access sensitive internal information and potentially render SAP systems unavailable.

Solution

The affected RFC function modules have been updated to enforce proper access restrictions. It is crucial to implement the correction instructions provided in this security note to mitigate the vulnerability.

CVSS

Score 7.6 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H

Affected components

  • SAP NetWeaver AS ABAP
  • SAP S4 HANA (SAP Landscape Transformation)

Full note on SAP: SAP Support Launchpad note 2993132

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More