Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in SAP Convergent Invoicing, SAP security note 2746946

SAP Note 2746946
SAP Security Note

SAP security note 2746946, "Missing Authorization Check in SAP Convergent Invoicing", is released on March 12, 2019. Below are the symptom and SAP recommended solution.

ComponentFinancial Accounting > Contract Accounts Receivable and Payable > Convergent Invoicing > Fiori-UI for Convergent Invoicing
TypeSAP Security Note
StatusReleased for Customer
Released onMarch 12, 2019

Description

Symptom

SAP Convergent Invoicing does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This can lead to:

  • Abuse of functionality restricted to specific user groups
  • Unauthorized access to read, modify, or delete restricted data

Solution

The affected functions have been updated to enforce proper access restrictions. To address this issue, you should implement the attached correction instructions or apply the relevant support package.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

References

Full note on SAP: SAP Support Launchpad note 2746946

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More