Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization check in SAP SRM, SAP security note 2490973

SAP Note 2490973

SAP security note 2490973, "Missing Authorization Check in SAP SRM". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP SRM does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Some well-known impacts of missing authorization checks are:

  • Abuse of functionality restricted to a particular user group
  • Read, modify, or delete restricted data

Solution

The affected functions have now been enforced to properly check access restrictions. Apply the attached correction instructions or import the corresponding support package.

Reason and prerequisites

The below notes are prerequisites of this note:

  • 1882417 – External check for Remote Function Call
  • 1988903 – Check whether a function module was called via external RFC

CVSS

Score 6.3/10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References

This note refers to

  • 1988903 – Check whether a function module was called via external RFC
  • 1882417 – External check for Remote Function Call

Referenced by

  • 2958401 – SRM calls to back-end ECC system don’t return requested data – follow-on note 2490973

Affected components

  • SAP_APPL 600
  • SAP_APPL 602
  • SAP_APPL 603
  • SAP_APPL 604
  • SAP_APPL 605
  • SAP_APPL 606
  • SAP_APPL 616
  • SAP_APPL 617
  • SAP_APPL 618

Full note on SAP: SAP Support Launchpad note 2490973

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More