Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0258 Missing Authorization check in SAP Disclosure Management, SAP security note 2724014

SAP Note 2724014

SAP security note 2724014, "[CVE-2019-0258] Missing Authorization Check in SAP Disclosure Management". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Disclosure Management does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Impacts of Missing Authorization Check:

  • Abuse of functionality restricted to a particular user group
  • Read, modify, or delete restricted data

Solution

Additional authorization checks have been implemented in SAP Disclosure Management 10.1 Stack 1300. You need to manually install the following updated components:

  • DM SERVER – APPL SERVER 10.1

For detailed instructions, see SAP Note 2672792.

Reason and prerequisites

You are using SAP Disclosure Management 10.1 Stack 12xx or earlier versions.

CVSS

Score 8.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

References

Affected components

  • DISCMGMS 1001

Full note on SAP: SAP Support Launchpad note 2724014

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More