SAP security note 2871167, “[CVE-2020-6199] Missing Authorization check in SAP ERP and S/4 HANA (MENA Certificate Management)”. Below are the symptom and SAP recommended solution.
Description
Symptom
MENA Certificate Management does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. A user without the appropriate authorization group can maintain company certificates.
Impacts of Missing Authorization Check:
- Abuse functionality restricted to a particular user group.
- Read, modify, or delete restricted data.
Solution
SAP recommends installing the solution by applying a Support Package. If an earlier installation is necessary, use the Note Assistant to implement the correction instruction. More information about the Note Assistant can be found on the SAP Service Marketplace.
Reason and prerequisites
The view does not have an authorization check. To address this, an authorization group is being added to enable the right users to access the view.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2871167
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
