SAP Security Note
Medium priority
SAP security note 2916562, "[CVE-2020-6270] Missing Authorization check in SAP NetWeaver AS ABAP (Banking Services)", is released on June 9, 2020. Below are the symptom and SAP recommended solution.
Description
Symptom
Banking Services does not perform necessary authorization checks for authenticated users. This vulnerability allows malicious users to make unauthorized changes to individual conditions, potentially leading to incorrect pricing. Impacts of missing authorization checks include:
- Abuse of functionality restricted to specific user groups
- Modification or deletion of restricted data
Exploitation of this vulnerability can result in unauthorized alterations to financial conditions, affecting the integrity of pricing data within the system.
Solution
To address this issue, import the relevant Support Package specified for your SAP NetWeaver AS ABAP release. Ensure that you are applying the correct Support Package for your specific software component version.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
References
- 1108710: Pricing: Handling individual conditions during changes
- 1119625: Correction: handling individual conditions in a changeover
- 1688870: Empty condition list leads to error during product change
Full note on SAP: SAP Support Launchpad note 2916562
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
