Description
This SAP Note provides you with changes to some S/4Hana ACR Brazil Option tools to address the issue when the system doesn’t perform the necessary authorization checks for an user, resulting in impacts such as abuse functionality restricted to a particular user group to read, modify or delete SPED reports’ data.
Available fix and Supported packages
- S4CORE | 103 | 103
- S4CORE | 104 | 104
- | SAPK-S4CLOUD_1911 |
- S4CORE 103 | SAPK-10303INS4CORE |
- S4CORE 104 | SAPK-10401INS4CORE |
Affected component
- FI-LOC-FI-BR
Advanced Compliance Reporting for Brazil
CVSS
Score: 5.3
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2814462