SAP Security Note
Medium priority
SAP security note 2915429, "[CVE-2020-6258] Missing Authorization check in SAP Identity Management", is a program error note released on May 12, 2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This issue pertains to a missing authorization check in SAP Identity Management, specifically in the REST API version 2 of Identity Management 8.0. The absence of proper authorization controls allows authenticated users to escalate privileges and access restricted data.
- Unauthorized access to functionalities restricted to specific user groups.
- Potential exposure of sensitive and restricted data.
Solution
To mitigate this vulnerability, apply the patch provided in the Support Packages & Patches section of SAP Note 2915429.
- Update Components: Ensure all SAP Identity Management components are updated to the corresponding Service Package level before applying the patch.
- Apply the Patch: Follow the instructions provided in the patch documentation.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References
- SAP Support Note 2915429
- CVE-2020-6258
Affected components
- IDMREST (8.0)
Full note on SAP: SAP Support Launchpad note 2915429
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
