SAP security note 2480837, "Missing Authorization check in Discrete Industries and Mill Products". Below are the symptom and SAP recommended solution.
Description
Symptom
Discrete Industries and Mill Products (IS-A, IS-HT, IS-ADEC-MEB) do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of Missing Authorization check are:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
- The affected functions have now been enforced to properly check access restrictions.
- Please implement the correction instructions.
- For certain areas like IS-HT and IS-A (XLO and SWP), the corrections are valid only for ERP Business Suite as they have been deprecated in S/4HANA.
Reason and prerequisites
Pre-requisite: the business function DIMP_SDUD is activated.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
References
This note refers to
- 1176609 – JITM: Erroneous JIT calls processed without any error
- 1296722 – JITR: Buffers refreshed on all servers although not desired
- 1906084 – EMJIT: Global data not updated although buffers updated
- 2030674 – Enforcing internal RFC in IS-A
- 2166570 – LBK1: Enabling time zone conversion for notification display in logbook
Full note on SAP: SAP Support Launchpad note 2480837
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
