Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in EA-DFPS monitoring tools, SAP security note 2376998

SAP Note 2376998
SAP Security Note
Medium priority

SAP security note 2376998, "Missing Authorization Check in EA-DFPS Monitoring Tools", is released on 13.12.2016. Below are the symptom and SAP recommended solution.

ComponentIS-DFS-BIT-DIS
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on13.12.2016
LanguageEnglish

Description

Symptom

Some functionality in Solution ‘Defense Forces and Public Security’ (EA-DFPS) for monitoring availability of servers in deployed scenarios lacks authorization and parameter checks.

Impacts of Missing Authorization Check:

  • Abuse functionality restricted to a particular user group.
  • Read, modify, or delete restricted data.

Solution

  • Remove RFC enablement of the function module.
  • Add consistency checks on parameters to avoid command injection.
  • Apply correction instructions: Apply Correction Instructions.

CVSS

Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Full note on SAP: SAP Support Launchpad note 2376998

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More