SAP Security Note
Medium priority
SAP security note 2885671, “[CVE-2020-6273] Missing Authorization check in SAP S/4 HANA (Fiori UI for General Ledger Accounting)”, is a program error note released on 11.08.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
In SAP S/4 HANA’s Fiori UI for General Ledger Accounting, an attacker with a non-administrative user account can identify and remove certain attachments belonging to another user without authorization. Removing the attachment does not depend on any action to be taken by the owning user. The attacker cannot view or alter the contents of the attachment; they can only remove it, making it unavailable to its owner.
Solution
The affected functions have been modified to properly check access restrictions. Please implement the correction instructions.
Reason and prerequisites
An attacker could perform malicious operations that would not be permitted had the access authorizations been properly checked.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Full note on SAP: SAP Support Launchpad note 2885671
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



