SAP Security Note
Medium priority
SAP security note 2458919, “Missing Authorization check in HCM E-recruiting”, is a program error note released on 27.02.2018. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
HCM E-recruiting does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of missing authorization check are:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
The following RFC function modules have been enforced with authority checks:
- HRRCF_MDL_QA_DOC_COMPLETE (if the right candidate is trying to access the activity)
- HR_RCF_ASSIGN_EE_TO_CANDIDATE (if the user is authorized for candidate maintenance)
Reason and prerequisites
Missing authority checks.
Affected components
- ERECRUIT 600
- ERECRUIT 603
- ERECRUIT 604
- ERECRUIT 605
- ERECRUIT 606
- ERECRUIT 616
- ERECRUIT 617
- ERECRUIT 800
- ERECRUIT 801
- ERECRUIT 802
Full note on SAP: SAP Support Launchpad note 2458919
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
