SAP security note 2805777, "[CVE-2019-0367] Missing Authorization Check in B2B Content Manager of B2B Add-On for SAP NetWeaver Process Integration". Below are the symptom and SAP recommended solution.
Description
Symptom
The B2B Content Manager of B2B Add-on for SAP NetWeaver Process Integration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of a missing authorization check are:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
Apply the latest patch version for the component indicated in the "Support Packages & Patches" section of this SAP Security Note.
Reason and prerequisites
EDI Content Manager does not perform authorization checks properly for all B2B standards.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2805777
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
