SAP security note 2864966, “[CVE-2020-6212] Missing Authorization Check in SAP ERP & S/4 HANA (Egypt localized Withholding Tax reports)”, covers the symptom and SAP recommended solution below.
Description
Symptom
Egypt localized withholding tax reports in SAP ERP & S/4 HANA, specifically ‘Clearing of Liabilities’ and ‘Remittance Statement and Summary’, lack necessary authorization checks for authenticated users. This vulnerability allows for privilege escalation, enabling unauthorized reading or modification of certain tax reports.
Impact:
- Unauthorized Data Access: Read, modify, or delete restricted tax data.
- Privilege Escalation: Gain higher access levels without proper authorization.
Solution
To mitigate this vulnerability, apply the correction instructions provided in SAP Security Note 2864966. SAP recommends installing the solution by applying a Support Package. Alternatively, you can use the Note Assistant to implement the correction instructions earlier.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N
References
- Referenced by SAP Note 2923054
Full note on SAP: SAP Support Launchpad note 2864966
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
