Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6316 Missing Authorization Check in SAP ERP and SAP S/4 HANA, SAP security note 2944188

SAP Note 2944188
Medium priority

SAP security note 2944188, "[CVE-2020-6316] Missing Authorization Check in SAP ERP and SAP S/4 HANA", is a program error note released on 09.03.2021. Below are the symptom, SAP recommended solution and the affected software components.

ComponentProject System > Information System
CategoryProgram error
PriorityMedium priority
Released on09.03.2021

Description

Symptom

Update 9th March 2021: this note has been re-released with updated ‘Correction instruction’ information.

SAP ERP and SAP S/4 HANA allow an authenticated user to view cost records for objects to which they do not have authorization in PS reporting.

An authenticated user with limited permissions can access sensitive cost records, potentially leading to unauthorized disclosure of financial information.

Solution

Implement the code changes via transaction SNOTE. After applying the note, users will only see objects within a project that they are authorized to access.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected components

  • SAP_APPL: 600 to 618
  • S4CORE: 100 to 104

Full note on SAP: SAP Support Launchpad note 2944188

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More