SAP security note 2367193, "Missing Authorization check in Cash Flow Statement report", is a program error note released on February 20, 2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Cash Flow Statement report does not perform necessary authorization checks for an authenticated user, resulting in potential escalation of privileges.
Known Impacts:
- Unauthorized abuse of functionalities restricted to specific user groups.
- Unauthorized access to restricted data.
Solution
Implement the correction instructions provided in this SAP Note via SNOTE or install the indicated Support Package.
No new authorization checks are added; there is no need to update roles.
Reason and prerequisites
The report lacks authorization checks for authenticated users accessing certain functions, which may lead to undesired system behavior.
CVSS
Score 4.3
Affected components
- SAP_APPL: Versions 600, 602, 603, 604, 605, 606, 616
- SAP_FIN: Versions 617, 618, 700, 720, 730
- S4CORE: Versions 100, 101
Full note on SAP: SAP Support Launchpad note 2367193
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



