SAP security note 2035923, "Missing authorization check in SD Credit cards", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can utilize functions of credit cards in Sales and Distribution (SD) to which access should be restricted. This vulnerability may lead to an escalation of privileges, potentially resulting in unauthorized actions within the system.
- Unauthorized access to credit card functions in SD.
- Potential escalation of user privileges without proper authorization checks.
Solution
Apply the provided correction to enforce proper authorization checks within the SD credit card functions.
Reason and prerequisites
The credit card functionality in SD lacks necessary authorization checks to verify an authenticated user’s permissions for accessing specific functions. This omission can lead to unintended system behavior and security breaches.
Affected components
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
- SAP_APPL 606
- SAP_APPL 616
- SAP_APPL 617
Full note on SAP: SAP Support Launchpad note 2035923
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
