Medium priority
SAP security note 2457909, "Missing Authorization Check in SCM Forecasting and Replenishment", is a program error note released on June 13, 2017. Below are the symptom and SAP recommended solution.
Description
Symptom
The SCM Forecasting and Replenishment module does not perform necessary authorization checks for authenticated users. This oversight can lead to unauthorized escalation of privileges.
Impacts:
- Abuse of Functionality: Users may access and misuse functionalities restricted to specific user groups.
- Data Exposure: Potential for reading, modifying, or deleting restricted data.
Solution
SAP has corrected the affected functions to enforce proper access restrictions. To mitigate this vulnerability, apply the necessary updates as outlined below:
- Using SNOTE Transaction: Implement the correction via the SNOTE transaction in your SAP system.
- Applying Support Packages: Alternatively, apply the corresponding support package provided by SAP.
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2457909
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



