SAP security note 2673959, "[CVE-2018-2461] Missing authorization check in SAP HCM Fiori app "People Profile"", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The SAP HCM Fiori app "People Profile" does not perform the necessary authorization checks for an authenticated user which may result in an escalation of privileges.
Some well-known impacts of the missing authorization check are:
- Abuse functionality restricted to particular user groups
- Read, modify or delete restricted data
Solution
The missing authorization check is added by this SAP Note.
Reason and prerequisites
Missing authorization check
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References
- SAP Note 2231850 – Employee Lookup, People Profile (ODATA): Employees without employee photo trigger exception in gateway
Affected components
- GBX01HR (600 to 600)
Full note on SAP: SAP Support Launchpad note 2673959
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
