SAP security note 2724014, "[CVE-2019-0258] Missing Authorization Check in SAP Disclosure Management". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Disclosure Management does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Impacts of Missing Authorization Check:
- Abuse of functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
Additional authorization checks have been implemented in SAP Disclosure Management 10.1 Stack 1300. You need to manually install the following updated components:
- DM SERVER – APPL SERVER 10.1
For detailed instructions, see SAP Note 2672792.
Reason and prerequisites
You are using SAP Disclosure Management 10.1 Stack 12xx or earlier versions.
CVSS
Score 8.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
References
Affected components
- DISCMGMS 1001
Full note on SAP: SAP Support Launchpad note 2724014
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



