SAP security note 1905591, "Missing authorization check in CRM business partner", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions related to business partner exchange that should have restricted access. This may result in an escalation of privileges.
Solution
Apply the relevant support package or correction instructions provided in this note.
Reason and prerequisites
Business partner exchange lacks authorization checks to verify an authenticated user's permissions for accessing certain functions. This may lead to undesired system behavior.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 1905591
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



