SAP security note 2865348, "[CVE-2020-6306] Missing Authorization check in SAP Leasing". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The authorization check is not performed when transaction FIEH01 is executed from the customer end, potentially allowing unauthorized access.
Solution
To mitigate this issue, additional switchable authorization checks have been implemented and are delivered inactive by default. Follow these steps to resolve the vulnerability:
Activate Switchable Authorization Checks: Follow the correction instructions to manually activate the additional authorization checks via transaction SACF.
- Start transaction SACF.
- Enter “FI_LA” as the scenario name and select “Scenario Definition”.
- Double-click on the FI_LA entry, then click “Change”.
- Use the “New” button to add the following authorization objects: F_BKPF_BED, F_BKPF_BUK, F_KNA1_BED, F_KNA1_BUK.
- Select all new entries and set their status to “Check active without restrictions”.
- Save your changes.
CVSS
Score 2.7 (Low) Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
References
Affected components
- SAP_APPL 618
- EA-APPL versions 600 through 617
Full note on SAP: SAP Support Launchpad note 2865348
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
