Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in S/4 HANA, SAP security note 2719440

SAP Note 2719440
SAP Security Note
Medium priority

SAP security note 2719440, "Missing Authorization check in S/4 HANA", is a program error note released on August 13, 2019. Below are the symptom and SAP recommended solution.

ComponentSupplier Relationship Management > SRM > Plug-In Interfaces
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onAugust 13, 2019
LanguageEnglish

Description

Symptom

S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Some well-known impacts of Missing Authorization check are:

  • Abuse functionality restricted to a particular user group
  • Read, modify, or delete restricted data

Solution

The affected functions have now been enforced to properly check access restrictions. Kindly apply the attached correction instructions or import the corresponding support package.

Reason and prerequisites

  • Note 1882417 – External check for Remote Function Call
  • Note 1988903 – Check whether a function module was called via external RFC

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References

Full note on SAP: SAP Support Launchpad note 2719440

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More