Medium priority
SAP security note 2953212, “[CVE-2020-6362] Incorrect Authorization in SAP Banking Services”, is released on 13.10.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Banking Services uses an incorrect authorization object in some of its reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability could lead to privilege escalation and violation of segregation of duties, which in turn could lead to service interruptions and system unavailability for the victim and users of the component.
Solution
The incorrect authorization object in vulnerable reports is replaced with the appropriate object. This note’s corrections are delivered with the corresponding support package or by implementing the correction instructions.
Reason and prerequisites
An incorrect authorization object was added via SAP Note 2583046.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
References
This note refers to
Full note on SAP: SAP Support Launchpad note 2953212
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
