Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6256 Missing Authorization check in SAP Master Data Governance, SAP security note 2912747

SAP Note 2912747
SAP Security Note
Medium priority

SAP security note 2912747, “[CVE-2020-6256] Missing Authorization Check in SAP Master Data Governance”, is a program error note released on 22.12.2020. Below are the symptom and the SAP recommended solution.

ComponentCA-MDG-AF (Cross-Application Components > Master Data Governance > Application Framework)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version7
StatusReleased for Customer
Released on22.12.2020
LanguageEnglish

Description

Symptom

UPDATE 22nd December 2020: This note has been re-released with updated ‘validity’ information. There have not been any changes done which require customer action.

An attacker can display an entity (for example, a Cost Center) that is currently changed by a change request in SAP Master Data Governance. The change request section will be displayed on the UI even though the user does not have the authority to display the type of the change request. This procedure also locks the change request, preventing an authorized user from making changes.

Solution

Apply the correction provided in this note. Without having display authorization for the change request type, you will receive an error page instead of the UI that displays the entity and the change request.

Reason and prerequisites

Currently, the authority for the change request type is only checked to determine the field status of the displayed entity and the visibility and state of buttons.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Full note on SAP: SAP Support Launchpad note 2912747

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More