Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6204 Missing Authorization check in SAP Treasury and Risk Management (Transaction Management), SAP security note 2841874

SAP Note 2841874

SAP security note 2841874, “[CVE-2020-6204] Missing Authorization Check in SAP Treasury and Risk Management (Transaction Management)”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Treasury and Risk Management (Transaction Management) allows an attacker with basic authorization to access product type information they would otherwise not have access to. The vulnerable selection query returns more records than it should, thus leading to an information disclosure. However, if an attacker tries to directly access details of an individual contract, the correct authorization will be checked and granted/denied accordingly.

Solution

Apply the preliminary correction via the Correction Instructions or implement the corresponding Support Package. After this note, authorization object T_DEAL_PD will be checked. If you have properly set up the authorization according to the proposal, you won’t be affected.

Reason and prerequisites

Transaction Management does not contain checks for an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected components

  • S4CORE
  • EA-FINSERV

Full note on SAP: SAP Support Launchpad note 2841874

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More