SAP Security Note
Medium priority
SAP security note 2912747, “[CVE-2020-6256] Missing Authorization Check in SAP Master Data Governance”, is a program error note released on 22.12.2020. Below are the symptom and the SAP recommended solution.
Description
Symptom
UPDATE 22nd December 2020: This note has been re-released with updated ‘validity’ information. There have not been any changes done which require customer action.
An attacker can display an entity (for example, a Cost Center) that is currently changed by a change request in SAP Master Data Governance. The change request section will be displayed on the UI even though the user does not have the authority to display the type of the change request. This procedure also locks the change request, preventing an authorized user from making changes.
Solution
Apply the correction provided in this note. Without having display authorization for the change request type, you will receive an error page instead of the UI that displays the entity and the change request.
Reason and prerequisites
Currently, the authority for the change request type is only checked to determine the field status of the displayed entity and the visibility and state of buttons.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Full note on SAP: SAP Support Launchpad note 2912747
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
