SAP security note 2727623, "[CVE-2019-0243] Missing Authorization check in SAP BW/4HANA", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
Under some circumstances, masterdata maintenance in SAP BW/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of Missing Authorization check are:
Abuse functionality restricted to a particular user group
Read, modify or delete restricted data
Solution
Implement Support Package 12 for SAP BW/4HANA 1.0 (SAPK-10012INDW4CORE) into your SAP BW/4HANA system.
Alternatively, you can use the correction instructions.
Before you use the correction instructions, make sure that you check SAP Note 1668882 and SAP Note 2248091 for transaction SNOTE.
Reason and prerequisites
The issue is a regression introduced with SAP BW/4HANA 1.0 SP08. Previous SPs are not vulnerable.
CVSS
Score 7.1 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2727623
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



