SAP security note 2993132, "[CVE-2020-26832] Missing Authorization check in SAP NetWeaver AS ABAP and SAP S4 HANA (SAP Landscape Transformation)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Landscape Transformation contains a vulnerability that allows a high-privileged user to execute an RFC function module without proper authorization checks. This flaw can enable attackers to access sensitive internal information and potentially render SAP systems unavailable.
Solution
The affected RFC function modules have been updated to enforce proper access restrictions. It is crucial to implement the correction instructions provided in this security note to mitigate the vulnerability.
CVSS
Score 7.6 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H
Affected components
- SAP NetWeaver AS ABAP
- SAP S4 HANA (SAP Landscape Transformation)
Full note on SAP: SAP Support Launchpad note 2993132
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
