SAP security note 3008422, "[CVE-2021-21467] Missing Authorization check in SAP Banking Services (Generic Market Data)", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
Due to a missing authorization check, a user with access to Generic Market Data of SAP Banking Services can also access protected Business Partner IDs. These IDs are confidential and could be misused by malicious actors.
Solution
The affected functions have been updated to enforce proper access restrictions. Please implement the correction instructions available here.
Reason and prerequisites
Missing authorization checks for an authenticated user.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Full note on SAP: SAP Support Launchpad note 3008422
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
