Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in Cash Flow Statement report, SAP security note 2367193

SAP Note 2367193SAP Security NoteMedium priority

SAP security note 2367193, "Missing Authorization check in Cash Flow Statement report", is a program error note released on February 20, 2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentMiscellaneous > Country/Region-Specific Developments > Russia > use FI-LOC-FI-RU
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released onFebruary 20, 2017
LanguageEnglish

Description

Symptom

The Cash Flow Statement report does not perform necessary authorization checks for an authenticated user, resulting in potential escalation of privileges.

Known Impacts:

  • Unauthorized abuse of functionalities restricted to specific user groups.
  • Unauthorized access to restricted data.

Solution

Implement the correction instructions provided in this SAP Note via SNOTE or install the indicated Support Package.

No new authorization checks are added; there is no need to update roles.

Reason and prerequisites

The report lacks authorization checks for authenticated users accessing certain functions, which may lead to undesired system behavior.

CVSS

Score 4.3

Affected components

  • SAP_APPL: Versions 600, 602, 603, 604, 605, 606, 616
  • SAP_FIN: Versions 617, 618, 700, 720, 730
  • S4CORE: Versions 100, 101

Full note on SAP: SAP Support Launchpad note 2367193

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More