SAP security note 2698996, "[CVE-2018-2494] Missing Authorization check in SAP Customizing Tools", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Customizing Tools do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of Missing Authorization check are:
- Abuse functionality restricted to a particular user group
- Read, modify or delete restricted data
Solution
Where SAP Customizing Tools access RFC destination management, an authorization check for S_RFC_ADM is implemented.
Please implement the Support Package mentioned in this SAP Note or the respective correction instruction.
CVSS
Score 8.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Affected components
- SAP_BASIS from 700 to 702
- SAP_BASIS from 710 to 730
- SAP_BASIS 731 to 731
- SAP_BASIS 740 to 740
- SAP_BASIS from 750 to 753
Full note on SAP: SAP Support Launchpad note 2698996
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



