SAP security note 2744937, "[CVE-2019-0280] Missing authorization check in SAP Treasury and Risk Management", is a program error note released on 14.05.2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Transaction Management in SAP Treasury and Risk Management (TRM) does not perform necessary authorization checks for an authenticated user, which can lead to an escalation of privileges.
Impacts of Missing Authorization Check:
- Abuse functionality restricted to a particular user group
- Unauthorized read, modify, or delete access to restricted data
Solution
Apply the preliminary correction via the provided Correction Instructions or implement the corresponding Support Package. After applying this note, authorization objects T_DEAL_DP and T_DEAL_PD will be enforced. Ensure that your authorization is properly set up according to the proposal to avoid being affected. Note that this issue has already been fixed in the cloud as of version 1905.
Reason and prerequisites
Transaction Management lacks authorization checks for certain functions, potentially resulting in unintended system behavior.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected components
- S4CORE: Versions 101, 102, 103
- EA-FINSERV: Versions 600, 603, 604, 605, 606, 616, 617, 618, 800
Full note on SAP: SAP Support Launchpad note 2744937
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
