Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in Direct-Input posting, SAP security note 2371610

SAP Note 2371610

SAP security note 2371610, "Missing Authorization Check in Direct-Input Posting", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

The direct-input interface of report RFBIBL00 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Abuse functionality restricted to a particular user group.

Read, modify, or delete restricted data.

Solution

Implement the attached correction instructions and perform the following manual steps:

  • Upload SACF-Scenario Definition: Open transaction SACF_TRANSFER and upload the SACF-scenario definition for scenario FI_DOC_DI_POST. The scenario definition is attached as FI_DOC_DI_POST.TXT.
  • Configure the Scenario: After uploading, configure the scenario in transaction SACF.
  • Activate Authorization Check: Create an active scenario for FI_DOC_DI_POST to activate the authorization check.

CVSS

Score 6.5 / 10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Full note on SAP: SAP Support Launchpad note 2371610

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More