Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization Check in SAP Central Payment, SAP security note 2730227

SAP Note 2730227
SAP Security Note
Medium priority

SAP security note 2730227, "Missing Authorization Check in SAP Central Payment", released on December 10, 2019. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFinancial Accounting > Central Finance > Central Payment (FI-CF-APR)
PriorityMedium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released onDecember 10, 2019

Description

Symptom

Central Payment historical data processing from source systems, introduced in SAP Note 2651431, fails to perform necessary authorization checks for authenticated users. This oversight can lead to privilege escalation, allowing unauthorized users to abuse functionalities restricted to specific user groups, and read, modify, or delete restricted data.

This can result in unauthorized access to sensitive functionalities and potential data breaches affecting confidentiality and integrity.

Solution

Implement the correction instructions provided in this note to ensure proper authorization checks are in place.

CVSS

Score 5.3 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

References

Affected components

  • SAP_APPL: Versions 600, 602, 603, 604, 605, 606, 616
  • SAP_FIN: Versions 617, 618, 700, 720, 730
  • S4CORE: Versions 100, 101, 102, 103

Full note on SAP: SAP Support Launchpad note 2730227

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More