SAP Security Note
Medium priority
SAP security note 2719440, "Missing Authorization check in S/4 HANA", is a program error note released on August 13, 2019. Below are the symptom and SAP recommended solution.
Description
Symptom
S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Some well-known impacts of Missing Authorization check are:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
The affected functions have now been enforced to properly check access restrictions. Kindly apply the attached correction instructions or import the corresponding support package.
Reason and prerequisites
- Note 1882417 – External check for Remote Function Call
- Note 1988903 – Check whether a function module was called via external RFC
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
- This document is causing side effects in SAP Note 2823146 – SRM Vendor Replication not working
Full note on SAP: SAP Support Launchpad note 2719440
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
