SAP Security Note
High priority
SAP security note 2723570, "[CVE-2019-0255] ABAP Platform provides access to Easy Access Menu", is a program error note released on 12.02.2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
ABAP Platform fails to validate the type of installation for an ABAP Server system correctly. This behavior may allow a business user to gain access to the full SAP Menu, specifically the "Easy Access Menu." This can be exploited by any user to elevate privileges and access business functionality.
Solution
The correction ensures that the installation type information is permanently stored. Additionally, backward navigation via function F15 ("Exit" in menu, or command "/n" in ok-code) is disabled for single transaction type User Interfaces. The correction is delivered with the SAP Kernel patch level as specified in this SAP Note.
CVSS
Score 7.1 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
References
- Transaction SMEN is locked in direct webgui
- Fiori Launchpad Tile to launch Backend transaction SMEN no longer works
Affected components
- KRNL64NUC: 7.74
- KRNL64UC: 7.73, 7.74
- KERNEL: 7.73, 7.74, 7.75
Full note on SAP: SAP Support Launchpad note 2723570
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
