SAP security note 2840520, "[CVE-2019-0386] – Missing authorization check in ERP Sales and SAP S/4HANA sales (SD-SLS)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Order processing in ERP Sales/S/4HANA Sales (SD-SLS) does not execute the required authorization checks for an authenticated user, which can result in an escalation of privileges. The known effects of the missing authorization check can include inappropriate use of functions whose use is restricted to certain user groups, and reading, modification, and deletion of data to which access should be restricted.
Solution
Implement the attached correction. As a result, the possibility of navigation from order processing to condition maintenance is deactivated.
Reason and prerequisites
The authorization objects of condition maintenance (V_KONH_VKO and V_KONH_VKS) were not maintained for the order processing functions such as VA03 in SU24.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected components
- SAP_APPL: Versions 600, 602, 603, 604, 605, 606, 616, 617, 618
- SAPSCORE: Version 117
- S4CORE: Versions 100, 101, 102, 103, 104
Full note on SAP: SAP Support Launchpad note 2840520
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
