SAP Security Note
SAP security note 2746946, "Missing Authorization Check in SAP Convergent Invoicing", is released on March 12, 2019. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Convergent Invoicing does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This can lead to:
- Abuse of functionality restricted to specific user groups
- Unauthorized access to read, modify, or delete restricted data
Solution
The affected functions have been updated to enforce proper access restrictions. To address this issue, you should implement the attached correction instructions or apply the relevant support package.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
References
This note refers to
Full note on SAP: SAP Support Launchpad note 2746946
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
