Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0386 – Missing authorization check in ERP Sales and SAP S/4HANA sales (SD-SLS), SAP security note 2840520

SAP Note 2840520

SAP security note 2840520, "[CVE-2019-0386] – Missing authorization check in ERP Sales and SAP S/4HANA sales (SD-SLS)". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Order processing in ERP Sales/S/4HANA Sales (SD-SLS) does not execute the required authorization checks for an authenticated user, which can result in an escalation of privileges. The known effects of the missing authorization check can include inappropriate use of functions whose use is restricted to certain user groups, and reading, modification, and deletion of data to which access should be restricted.

Solution

Implement the attached correction. As a result, the possibility of navigation from order processing to condition maintenance is deactivated.

Reason and prerequisites

The authorization objects of condition maintenance (V_KONH_VKO and V_KONH_VKS) were not maintained for the order processing functions such as VA03 in SU24.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected components

  • SAP_APPL: Versions 600, 602, 603, 604, 605, 606, 616, 617, 618
  • SAPSCORE: Version 117
  • S4CORE: Versions 100, 101, 102, 103, 104

Full note on SAP: SAP Support Launchpad note 2840520

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More