SAP security note 2645133, "[CVE-2018-2454] Missing Authorization check in SAP Enterprise Financial Services", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Enterprise Financial Services does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
The affected functions have now been enforced to properly check access restrictions. Please implement the attached correction instruction using transaction SNOTE.
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References
This note refers to
- SAP Note 1513313 – RFBKPRENOTEARCDISPLAY short dump DBIF_RSQL_INVALID_RSQL (Component: IS-B-BCA-AM)
- SAP Note 2588167 – Report FIPR_ATTRTREE_CHECK: Incomplete Report Attributes (Component: IS-B-BCA)
- SAP Note 2644818 – BKK_ARC_PRENOTE_DISPLAY: E131(BKK_PRENOTE) "Invalid parameter while reading from archive" (Component: IS-B-BCA-AM)
Full note on SAP: SAP Support Launchpad note 2645133
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
