SAP security note 2693083, "[CVE-2018-2481] Leveraging privileges by customer transaction code". Below are the symptom and the SAP recommended solution.
Description
Symptom
In some SAP standard roles, a transaction code reserved for customers is used. By implementing such a transaction code, a malicious user may execute unauthorized transaction functionality.
Solution
The transaction code ZPTTNO_TIME is removed from the standard role SAP_PS_RM_PRO_RECMANAGER.
- Review your assignment of the SAP_PS_RM_PRO_RECMANAGER role.
- Apply the support packages mentioned in this SAP Note to correct the role.
Reason and prerequisites
Profile authorization can be assigned to a user incidentally. If the user is aware of this fact, they may develop their own transaction with malicious functionality and execute the custom transaction. This enables the user to escalate their privileges. The user needs permission to develop such a transaction and to transport it to the productive system at the end.
CVSS
Score 7.6/10 Vector: AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
References
- This document refers to SAP Note 2392860
Full note on SAP: SAP Support Launchpad note 2693083
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
