Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Missing authorization check in VIRSA and VIRSANH, SAP security note 1690942

Description

An authenticated user can use functions of VIRSA and VIRSANH to which access should be restricted. This may result in an escalation of privileges

Available fix and Supported packages

  • VIRSA | 400_46C | 400_46C
  • VIRSA | 400_620 | 400_620
  • VIRSA | 400_640 | 400_640
  • VIRSA | 400_700 | 400_700
  • VIRSANH | 400_46C | 400_46C
  • VIRSANH | 400_620 | 400_620
  • VIRSANH | 400_640 | 400_640
  • VIRSANH | 400_700 | 400_700
  • VIRSANH | 520_46C | 520_46C
  • VIRSANH | 520_620 | 520_620
  • VIRSANH | 520_640 | 520_640
  • VIRSANH | 520_700 | 520_700
  • VIRSANH | 530_46C | 530_46C
  • VIRSANH | 530_620 | 530_620
  • VIRSANH | 530_640 | 530_640
  • VIRSANH | 530_700 | 530_700
  • VIRSANH | 530_710 | 530_710
  • VIRSANH | 530_731 | 530_731
  • GRCPINW | V1000_46C | V1000_46C
  • GRCPINW | V1000_620 | V1000_620
  • VIRSA 400_46C | SAPK-V4C20INVIRSA |
  • VIRSA 400_620 | SAPK-V4719INVIRSA |
  • VIRSA 400_640 | SAPK-V4E20INVIRSA |
  • VIRSA 400_700 | SAPK-47013INVIRSA |
  • VIRSANH 520_46C | SAPK-52016INVIRSANH |
  • VIRSANH 520_620 | SAPK-52117INVIRSANH |
  • VIRSANH 520_640 | SAPK-52217INVIRSANH |
  • VIRSANH 520_700 | SAPK-52317INVIRSANH |
  • VIRSANH 400_46C | SAPK-40012INVIRSANH |
  • VIRSANH 400_620 | SAPK-40112INVIRSANH |
  • VIRSANH 400_640 | SAPK-40212INVIRSANH |
  • VIRSANH 400_700 | SAPK-40313INVIRSANH |
  • VIRSANH 530_620 | SAPK-53120INVIRSANH |
  • VIRSANH 530_46C | SAPK-53020INVIRSANH |
  • VIRSANH 530_640 | SAPK-53220INVIRSANH |
  • VIRSANH 530_700 | SAPK-53320INVIRSANH |
  • VIRSANH 530_710 | SAPK-53414INVIRSANH |
  • VIRSANH 530_731 | 530_731 |
  • GRCPINW V1000_620 | SAPK-10109INGRCPINW |
  • GRCPINW V1000_640 | SAPK-10209INGRCPINW |

Affected component

    GRC-SAC-EAM
    Emergency Access Management

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1690942

TAGS

#Authorization
#authorization-check
#VIRSA
#VIRSANH

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,