Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2481 Leveraging privileges by customer transaction code, SAP security note 2693083

SAP Note 2693083

SAP security note 2693083, "[CVE-2018-2481] Leveraging privileges by customer transaction code". Below are the symptom and the SAP recommended solution.

Description

Symptom

In some SAP standard roles, a transaction code reserved for customers is used. By implementing such a transaction code, a malicious user may execute unauthorized transaction functionality.

Solution

The transaction code ZPTTNO_TIME is removed from the standard role SAP_PS_RM_PRO_RECMANAGER.

  • Review your assignment of the SAP_PS_RM_PRO_RECMANAGER role.
  • Apply the support packages mentioned in this SAP Note to correct the role.

Reason and prerequisites

Profile authorization can be assigned to a user incidentally. If the user is aware of this fact, they may develop their own transaction with malicious functionality and execute the custom transaction. This enables the user to escalate their privileges. The user needs permission to develop such a transaction and to transport it to the productive system at the end.

CVSS

Score 7.6/10 Vector: AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

References

Full note on SAP: SAP Support Launchpad note 2693083

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More