Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Authorization check for transactions calls in performance, SAP security note 1475470

SAP Note 1475470

SAP security note 1475470, "Authorization check for transactions calls in performance". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A vulnerability exists in the programs related to performance within the SAP Supplier Relationship Management (SAP SRM) solution. This vulnerability allows hackers to access restricted SAP transactions at runtime, which can lead to:

  • Manipulation of Business Logic resulting in inconsistent data states.
  • Violation of regulatory compliance due to unprivileged access to critical business logic.

Solution

Implement the attached corrections or import the relevant support package to address the vulnerability.

Dynamic transaction calls are now validated using appropriate authority checks, ensuring that only authorized users can execute them.

Reason and prerequisites

This issue is caused by a program error due to missing authorization checks during dynamic calls to transactions from SRM programs. Malicious users can exploit this vulnerability to execute unauthorized transactions.

Affected components

  • SAP SRM 4.0
  • SAP SRM 5.0
  • SAP SRM 6.0
  • SAP SRM 7.0
  • SAP SRM 7.01

Full note on SAP: SAP Support Launchpad note 1475470

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More