Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0325 Missing Authorization check in SAP ERP HCM, SAP security note 2798133

SAP Note 2798133

SAP security note 2798133, "[CVE-2019-0325] Missing Authorization Check in SAP ERP HCM". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP ERP HCM Spain does not perform necessary authorization checks for a report that reads payroll data of employees in a certain area. Due to this, under certain conditions, users who previously had authorization to payroll data of an employee, which was later revoked, may retain access to the same data.

This vulnerability allows unauthorized users to access sensitive payroll data, potentially leading to data leakage and compliance issues.

Solution

The affected functions have been updated to properly enforce access restrictions. Please implement the correction instructions.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected components

  • SAP_HRCES: Versions 600, 604, 608

Full note on SAP: SAP Support Launchpad note 2798133

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More