Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in SAP ERP Defence Forces and Public Security, SAP security note 2378417

SAP Note 2378417
SAP Security Note
Medium priority

SAP security note 2378417, "Missing Authorization check in SAP ERP Defence Forces and Public Security", released on 10.01.2017. Below are the symptom and SAP recommended solution.

ComponentIS-DFS-BIT (Industry-Specific Components > Defense Forces and Public Security > Basis Technology R/3)
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on10.01.2017

Description

Symptom

EA-DFPS does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Impacts of Missing Authorization check include:

  • Abuse of functionality restricted to a particular user group
  • Ability to read, modify, or delete restricted data

Solution

An additional authorization check has been added for the function: /ISDFPS/USOB_AUTHVALTRC_DELETE.

CVSS

Score 5.0 Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2378417

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More