Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6258 Missing Authorization check in SAP Identity Management, SAP security note 2915429

SAP Note 2915429
SAP Security Note
Medium priority

SAP security note 2915429, "[CVE-2020-6258] Missing Authorization check in SAP Identity Management", is a program error note released on May 12, 2020. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Identity and Access Management > Identity Management (BC-IAM-IDM)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onMay 12, 2020

Description

Symptom

This issue pertains to a missing authorization check in SAP Identity Management, specifically in the REST API version 2 of Identity Management 8.0. The absence of proper authorization controls allows authenticated users to escalate privileges and access restricted data.

  • Unauthorized access to functionalities restricted to specific user groups.
  • Potential exposure of sensitive and restricted data.

Solution

To mitigate this vulnerability, apply the patch provided in the Support Packages & Patches section of SAP Note 2915429.

  • Update Components: Ensure all SAP Identity Management components are updated to the corresponding Service Package level before applying the patch.
  • Apply the Patch: Follow the instructions provided in the patch documentation.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References

  • SAP Support Note 2915429
  • CVE-2020-6258

Affected components

  • IDMREST (8.0)

Full note on SAP: SAP Support Launchpad note 2915429

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More