SAP security note 2378448, "Missing Authorization check in SAP ERP Defence Forces and Public Security". Below are the symptom and SAP recommended solution.
Description
Symptom
EA-DFPS synchronization mechanisms do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Impacts of Missing Authorization Check:
- Abuse functionality restricted to a particular user group
- Read, modify, or delete restricted data
Solution
Additional authorization checks have been added for the function /ISDFPS/BAPI_LOGSYS_SYNCHRONIZ.
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2378448
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
