SAP Security Note
Medium priority
SAP security note 2491578, "Missing authorization check in Loans Management", is a program error note released on 13.10.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Loans Management does not execute the required authorization checks for an authenticated user, which may result in an escalation of privileges.
The known effects of the missing authorization check include:
- Fraudulent or incorrect use of functions that should be restricted to certain user groups.
- Ability to read, modify, or delete data to which access should be restricted.
Solution
New authorization checks have been implemented to ensure that users have the appropriate permissions before accessing sensitive functions within Loans Management.
Reason and prerequisites
Loans Management lacks authorization checks for verifying an authenticated user’s permissions to access certain functions. This absence can lead to undesired system behavior.
References
Affected components
- SAPSCORE: 110
- S4CORE: 101, 102
- EA-FINSERV: 617, 618, 800
Full note on SAP: SAP Support Launchpad note 2491578
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
