Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6212 Missing Authorization Check in SAP ERP & S/4 HANA (Egypt localized Withholding Tax reports), SAP security note 2864966

SAP Note 2864966

SAP security note 2864966, “[CVE-2020-6212] Missing Authorization Check in SAP ERP & S/4 HANA (Egypt localized Withholding Tax reports)”, covers the symptom and SAP recommended solution below.

ComponentMiscellaneous > Country/Region-Specific Developments > Egypt > Financial Accounting (XX-CSC-EG-FI)

Description

Symptom

Egypt localized withholding tax reports in SAP ERP & S/4 HANA, specifically ‘Clearing of Liabilities’ and ‘Remittance Statement and Summary’, lack necessary authorization checks for authenticated users. This vulnerability allows for privilege escalation, enabling unauthorized reading or modification of certain tax reports.

Impact:

  • Unauthorized Data Access: Read, modify, or delete restricted tax data.
  • Privilege Escalation: Gain higher access levels without proper authorization.

Solution

To mitigate this vulnerability, apply the correction instructions provided in SAP Security Note 2864966. SAP recommends installing the solution by applying a Support Package. Alternatively, you can use the Note Assistant to implement the correction instructions earlier.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N

References

Full note on SAP: SAP Support Launchpad note 2864966

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More