Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Leveraging privileges by customer transaction code, SAP security note 2392860

SAP Note 2392860

SAP security note 2392860, "Leveraging privileges by customer transaction code". Below are the symptom and SAP recommended solution.

Description

Symptom

In some SAP standard roles, a transaction code reserved for customers (ZPTTNO_TIME) is used. A malicious user with access to this transaction code can execute unauthorized functionalities, leading to privilege escalation. This requires the user to have permissions to develop and transport custom transactions to the productive system.

Solution

To mitigate this vulnerability, the transaction code ZPTTNO_TIME has been removed from the standard roles:

  • SAP_PS_RM_PRO_ADMIN
  • SAP_PS_RM_PRO_REVIEWER

Review and adjust the assignments of these roles within your SAP environment. Apply the support packages listed in this SAP Note to ensure the roles are corrected.

CVSS

Score 8.0 / 10 Vector: AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Full note on SAP: SAP Support Launchpad note 2392860

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More