Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6273 Missing Authorization check in SAP S/4 HANA (Fiori UI for General Ledger Accounting), SAP security note 2885671

SAP Note 2885671
SAP Security Note
Medium priority

SAP security note 2885671, “[CVE-2020-6273] Missing Authorization check in SAP S/4 HANA (Fiori UI for General Ledger Accounting)”, is a program error note released on 11.08.2020. Below are the symptom and SAP recommended solution.

ComponentFI-FIO-GL (Financial Accounting > Fiori UI for Financial Accounting > Fiori UI for General Ledger Accounting)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version8
StatusReleased for Customer
Released on11.08.2020
LanguageEnglish

Description

Symptom

In SAP S/4 HANA’s Fiori UI for General Ledger Accounting, an attacker with a non-administrative user account can identify and remove certain attachments belonging to another user without authorization. Removing the attachment does not depend on any action to be taken by the owning user. The attacker cannot view or alter the contents of the attachment; they can only remove it, making it unavailable to its owner.

Solution

The affected functions have been modified to properly check access restrictions. Please implement the correction instructions.

Reason and prerequisites

An attacker could perform malicious operations that would not be permitted had the access authorizations been properly checked.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Full note on SAP: SAP Support Launchpad note 2885671

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More