Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2461 Missing authorization check in SAP HCM Fiori app “People Profile”, SAP security note 2673959

SAP Note 2673959

SAP security note 2673959, "[CVE-2018-2461] Missing authorization check in SAP HCM Fiori app "People Profile"", is a note. Below are the symptom, SAP recommended solution and the affected software components.

ComponentPA-FIO

Description

Symptom

The SAP HCM Fiori app "People Profile" does not perform the necessary authorization checks for an authenticated user which may result in an escalation of privileges.

Some well-known impacts of the missing authorization check are:

  • Abuse functionality restricted to particular user groups
  • Read, modify or delete restricted data

Solution

The missing authorization check is added by this SAP Note.

Reason and prerequisites

Missing authorization check

CVSS

Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References

  • SAP Note 2231850 – Employee Lookup, People Profile (ODATA): Employees without employee photo trigger exception in gateway

Affected components

  • GBX01HR (600 to 600)

Full note on SAP: SAP Support Launchpad note 2673959

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More