SAP security note 2857511, “[CVE-2020-6188] Missing Authorization check in SAP ERP and S/4 HANA (VAT Pro-Rata reports)”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
VAT Pro-Rata reports do not perform necessary authorization checks for an authenticated user.
Some well-known impacts of Missing Authorization check are:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
The affected functions have now been enforced to properly check the access restrictions.
Important: It is assumed that the user profiles for these functions already contain the authorization for object F_BKPF_BUK for ACTVT 01. If not, this must be added to the users’ authorizations.
As a general rule, SAP recommends that you install a solution by applying a Support Package. However, if you need to install this solution earlier, use the Note Assistant to implement the correction instruction. You can find more information about the Note Assistant in SAP Service Marketplace, under service.sap.com/note-assistant.
Reason and prerequisites
The report is executed in Update Run mode. Other execution modes are not affected.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N
Affected components
- SAP_APPL, Releases 600 to 616
- SAP_FIN, Releases 617 to 730
- S4CORE, Releases 100 to 104
Full note on SAP: SAP Support Launchpad note 2857511
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
