Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6306 Missing Authorization check in SAP Leasing, SAP security note 2865348

Description

This SAP note describes additional switchable authorization checks for transaction FIEH01 in SAP Leasing (FI-LA).   

Available fix and Supported packages

  • SAP_APPL | 618 | 618
  • EA-APPL | 600 | 600
  • EA-APPL | 602 | 602
  • EA-APPL | 603 | 603
  • EA-APPL | 604 | 604
  • EA-APPL | 605 | 605
  • EA-APPL | 606 | 606
  • EA-APPL | 616 | 616
  • EA-APPL | 617 | 617
  • SAP_APPL 618 | SAPK-61814INSAPAPPL |
  • EA-APPL 616 | SAPK-61614INEAAPPL |
  • EA-APPL 617 | SAPK-61720INEAAPPL |
  • EA-APPL 600 | SAPKGPAD33 |
  • EA-APPL 602 | SAPK-60223INEAAPPL |
  • EA-APPL 603 | SAPK-60322INEAAPPL |
  • EA-APPL 604 | SAPK-60423INEAAPPL |
  • EA-APPL 605 | SAPK-60520INEAAPPL |
  • EA-APPL 606 | SAPK-60626INEAAPPL |

Affected component

    FI-LA
    Lease Accounting Engine

CVSS

Score: 2.7
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/2865348

TAGS

#SACF
#RFC
#authorization
#LAE
#FI-LA
#leasing-contract-transfer
#reprocessing
#FIEH01
#&160-CVE-2020-6306

More to explorer

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.