SAP Security Note
Medium priority
SAP security note 2378417, "Missing Authorization check in SAP ERP Defence Forces and Public Security", released on 10.01.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
EA-DFPS does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Impacts of Missing Authorization check include:
- Abuse of functionality restricted to a particular user group
- Ability to read, modify, or delete restricted data
Solution
An additional authorization check has been added for the function: /ISDFPS/USOB_AUTHVALTRC_DELETE.
CVSS
Score 5.0 Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2378417
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
