SAP security note 2377067, “Missing Authorization check in EA-DFPS synchronization mechanisms”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The solution Defense Forces and Public Security (EA-DFPS) does not perform necessary authorization checks for authenticated users in its synchronization mechanisms, resulting in potential escalation of privileges.
Impacts of Missing Authorization Checks:
- Abuse of functionality restricted to specific user groups
- Ability to read, modify, or delete restricted data
Solution
Authority checks have been added to address the issue. Please follow the Correction Instructions to implement the necessary changes.
Reason and prerequisites
Before implementing this security note, ensure the following SAP Notes are applied:
- 1095825 – DFPS – only change tRFC related Partner-Profiles
- 2025390 – Missing authorization check in function module /ISDFPS/ALE_SET_SYSTEM_STATE
CVSS
Score 6.4 Vector: NLLN | C | NLL
References
Affected components
- EA-DFPS: Versions 600, 603, 604, 605, 606, 616, 617, 618, 800, 801
Full note on SAP: SAP Support Launchpad note 2377067
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
