Medium priority
SAP security note 2814462, "Missing Authorization Check in S/4Hana ACR Brazil Option Features", released on November 26, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The system does not enforce required authorization checks, enabling users to abuse functionalities restricted to specific user groups. This affects the ability to manage SPED reports such as ECD, ECF, EFD ICMS IPI, and EFD Contribuições, which can allow unauthorized users to read, modify, or delete SPED reports’ data.
Solution
Implementing this SAP Note will ensure that the following S/4Hana ACR Brazil Option tools perform proper authorization checks:
- Generate Template File for SPED Registers (
/TMF/SHADOW_SHEET_GENERATE) - Import Complementary Data to SPED Registers (
/TMF/IMPEXL_GUI) - Delete Complementary Data from SPED Registers (
/TMF/IMPDELEXL_GUI)
CVSS
Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L
Affected components
- S4CORE: Versions 103, 104
Full note on SAP: SAP Support Launchpad note 2814462
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



