Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2021-21467 Missing Authorization check in SAP Banking Services (Generic Market Data), SAP security note 3008422

SAP Note 3008422

SAP security note 3008422, "[CVE-2021-21467] Missing Authorization check in SAP Banking Services (Generic Market Data)", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

Due to a missing authorization check, a user with access to Generic Market Data of SAP Banking Services can also access protected Business Partner IDs. These IDs are confidential and could be misused by malicious actors.

Solution

The affected functions have been updated to enforce proper access restrictions. Please implement the correction instructions available here.

Reason and prerequisites

Missing authorization checks for an authenticated user.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Full note on SAP: SAP Support Launchpad note 3008422

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More