Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6188 Missing Authorization check in SAP ERP and S/4 HANA (VAT Pro-Rata reports), SAP security note 2857511

SAP Note 2857511

SAP security note 2857511, “[CVE-2020-6188] Missing Authorization check in SAP ERP and S/4 HANA (VAT Pro-Rata reports)”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

VAT Pro-Rata reports do not perform necessary authorization checks for an authenticated user.

Some well-known impacts of Missing Authorization check are:

  • Abuse functionality restricted to a particular user group
  • Read, modify, or delete restricted data

Solution

The affected functions have now been enforced to properly check the access restrictions.

Important: It is assumed that the user profiles for these functions already contain the authorization for object F_BKPF_BUK for ACTVT 01. If not, this must be added to the users’ authorizations.

As a general rule, SAP recommends that you install a solution by applying a Support Package. However, if you need to install this solution earlier, use the Note Assistant to implement the correction instruction. You can find more information about the Note Assistant in SAP Service Marketplace, under service.sap.com/note-assistant.

Reason and prerequisites

The report is executed in Update Run mode. Other execution modes are not affected.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N

Affected components

  • SAP_APPL, Releases 600 to 616
  • SAP_FIN, Releases 617 to 730
  • S4CORE, Releases 100 to 104

Full note on SAP: SAP Support Launchpad note 2857511

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More