Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in Manage Substitutions – Products and Manage Exclusions – Products, SAP security note 2973100

SAP Note 2973100SAP Security NoteLow priority

SAP security note 2973100, "Missing Authorization check in Manage Substitutions – Products and Manage Exclusions – Products", is a program error note released on October 13, 2020. Below are the symptom and SAP recommended solution.

ComponentCross-Application Components > Available to Promise (ATP) > ATP: Master Data Substitution
CategoryProgram Error
PriorityCorrection with Low Priority
TypeSAP Security Note
StatusReleased for Customer
Released onOctober 13, 2020

Description

Symptom

The Fiori applications Manage Substitutions – Products and Manage Exclusions – Products do not perform necessary authorization checks for authenticated users. This oversight allows users to escalate privileges by:

  • Abusing functionality restricted to specific user groups
  • Modifying restricted data

Solution

The affected functions have been updated to enforce proper access restrictions. To address this issue, please implement the correction instructions provided in the support package.

Reason and prerequisites

In the mentioned Fiori applications, an authenticated user can modify the status of substitutions and exclusions without proper authorization. This vulnerability can lead to data integrity issues within the product substitution process.

CVSS

Score 3.6 Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2973100

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More