SAP security note 2545842, "[CVE-2018-2381] Missing Authorization Check in SAP ERP Financials Information System", is a note released on February 12, 2018. Below are the symptom, reason and prerequisites, SAP recommended solution and CVSS score.
Description
Symptom
SAP ERP Financials Information System does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This can lead to:
- Abuse of functionality restricted to specific user groups
- Unauthorized read, modify, or delete operations on restricted data
Solution
Implement the recommended Support Package or follow the correction instructions provided in this SAP Note to address the authorization vulnerability.
Reason and prerequisites
Ensure that SAP Note 2450963 ("Line Item Browsers: PIVB") is applied for your respective software component versions.
CVSS
Score 6.3/10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
- CVE-2018-2381
Full note on SAP: SAP Support Launchpad note 2545842
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
