SAP security note 2250863, "Missing authorization check in CIN Journal Voucher", is a program error note released on 26.03.2019. Below are the symptom and the SAP recommended solution.
Description
Symptom
An authenticated user can use functions of CIN Journal Voucher to which access should be restricted. This may result in an escalation of privileges.
Solution
AUTHORITY_CHECK is added for FB00. Implement support package or correction instructions.
Reason and prerequisites
CIN Journal Voucher does not contain authorization checks for checking an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
CVSS
Score 3.7 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2250863
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
