SAP Security Note
Medium priority
SAP security note 2376524, "Missing Authorization Check in SAP ERP Defence Forces and Public Security", is a program error note released on 10.01.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
EA-DFPS does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of Missing Authorization check are:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
Additional authorization checks have been added for the following functions:
/ISDFPS/RFC_RSLG_WRITE_SYSLOG/ISDFPS/SYNC_SLOG_WRITE_ENTRY
CVSS
Score 5.4 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2376524
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
