Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in VIRSA and VIRSANH, SAP security note 1690942

Description

An authenticated user can use functions of VIRSA and VIRSANH to which access should be restricted. This may result in an escalation of privileges

Available fix and Supported packages

  • VIRSA | 400_46C | 400_46C
  • VIRSA | 400_620 | 400_620
  • VIRSA | 400_640 | 400_640
  • VIRSA | 400_700 | 400_700
  • VIRSANH | 400_46C | 400_46C
  • VIRSANH | 400_620 | 400_620
  • VIRSANH | 400_640 | 400_640
  • VIRSANH | 400_700 | 400_700
  • VIRSANH | 520_46C | 520_46C
  • VIRSANH | 520_620 | 520_620
  • VIRSANH | 520_640 | 520_640
  • VIRSANH | 520_700 | 520_700
  • VIRSANH | 530_46C | 530_46C
  • VIRSANH | 530_620 | 530_620
  • VIRSANH | 530_640 | 530_640
  • VIRSANH | 530_700 | 530_700
  • VIRSANH | 530_710 | 530_710
  • VIRSANH | 530_731 | 530_731
  • GRCPINW | V1000_46C | V1000_46C
  • GRCPINW | V1000_620 | V1000_620
  • VIRSA 400_46C | SAPK-V4C20INVIRSA |
  • VIRSA 400_620 | SAPK-V4719INVIRSA |
  • VIRSA 400_640 | SAPK-V4E20INVIRSA |
  • VIRSA 400_700 | SAPK-47013INVIRSA |
  • VIRSANH 520_46C | SAPK-52016INVIRSANH |
  • VIRSANH 520_620 | SAPK-52117INVIRSANH |
  • VIRSANH 520_640 | SAPK-52217INVIRSANH |
  • VIRSANH 520_700 | SAPK-52317INVIRSANH |
  • VIRSANH 400_46C | SAPK-40012INVIRSANH |
  • VIRSANH 400_620 | SAPK-40112INVIRSANH |
  • VIRSANH 400_640 | SAPK-40212INVIRSANH |
  • VIRSANH 400_700 | SAPK-40313INVIRSANH |
  • VIRSANH 530_620 | SAPK-53120INVIRSANH |
  • VIRSANH 530_46C | SAPK-53020INVIRSANH |
  • VIRSANH 530_640 | SAPK-53220INVIRSANH |
  • VIRSANH 530_700 | SAPK-53320INVIRSANH |
  • VIRSANH 530_710 | SAPK-53414INVIRSANH |
  • VIRSANH 530_731 | 530_731 |
  • GRCPINW V1000_620 | SAPK-10109INGRCPINW |
  • GRCPINW V1000_640 | SAPK-10209INGRCPINW |

Affected component

    GRC-SAC-EAM
    Emergency Access Management

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1690942

TAGS

#Authorization
#authorization-check
#VIRSA
#VIRSANH

Explore More

RedRays AI for ABAP Code Security

Empowering Secure, Efficient, and Compliant SAP ABAP Development—in Real Time and Without Data Retention In today’s rapidly evolving business landscape, organizations increasingly

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.