SAP Security Note
Medium priority
SAP security note 2730227, "Missing Authorization Check in SAP Central Payment", released on December 10, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Central Payment historical data processing from source systems, introduced in SAP Note 2651431, fails to perform necessary authorization checks for authenticated users. This oversight can lead to privilege escalation, allowing unauthorized users to abuse functionalities restricted to specific user groups, and read, modify, or delete restricted data.
This can result in unauthorized access to sensitive functionalities and potential data breaches affecting confidentiality and integrity.
Solution
Implement the correction instructions provided in this note to ensure proper authorization checks are in place.
CVSS
Score 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
References
Affected components
- SAP_APPL: Versions 600, 602, 603, 604, 605, 606, 616
- SAP_FIN: Versions 617, 618, 700, 720, 730
- S4CORE: Versions 100, 101, 102, 103
Full note on SAP: SAP Support Launchpad note 2730227
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
