Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0280 Missing authorization check in SAP Treasury and Risk Management, SAP security note 2744937

SAP Note 2744937SAP Security NoteMedium priority

SAP security note 2744937, "[CVE-2019-0280] Missing authorization check in SAP Treasury and Risk Management", is a program error note released on 14.05.2019. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on14.05.2019
LanguageEnglish

Description

Symptom

Transaction Management in SAP Treasury and Risk Management (TRM) does not perform necessary authorization checks for an authenticated user, which can lead to an escalation of privileges.

Impacts of Missing Authorization Check:

  • Abuse functionality restricted to a particular user group
  • Unauthorized read, modify, or delete access to restricted data

Solution

Apply the preliminary correction via the provided Correction Instructions or implement the corresponding Support Package. After applying this note, authorization objects T_DEAL_DP and T_DEAL_PD will be enforced. Ensure that your authorization is properly set up according to the proposal to avoid being affected. Note that this issue has already been fixed in the cloud as of version 1905.

Reason and prerequisites

Transaction Management lacks authorization checks for certain functions, potentially resulting in unintended system behavior.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected components

  • S4CORE: Versions 101, 102, 103
  • EA-FINSERV: Versions 600, 603, 604, 605, 606, 616, 617, 618, 800

Full note on SAP: SAP Support Launchpad note 2744937

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More