SAP security note 2519562, "Missing Authorization check in XX-CSC-AR-LO", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
UPDATE 30th August 2018: This note has been re-released with updated ‘CVSS Information’ and ‘Solution’ information.
You are executing a task in the Argentina Electronic Invoice (AEI) component; however, it does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of missing authorization checks are:
- Abuse functionality restricted to a particular user group.
- Read, modify, or delete restricted data.
Solution
After applying this SAP Note, an Authority Check for Argentina Electronic Invoice will be performed in each functionality listed below:
BAPI_AR_WS_ARCHIVE_XMLJ_1A_WS_EXP_REMOTE_CALLJ_1A_WS_REMOTE_CALL
Reason and prerequisites
This SAP Note is relevant only for Argentina.
CVSS
Score 6.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
Referenced by
- SAP Note 2370680 – Argentina Electronic Invoice RG 2485/4291 Troubleshooting Guide
- SAP Note 2370724 – Argentina Electronic Invoice RG 2904 Troubleshooting Guide
- SAP Note 2370720 – Argentina Electronic Invoice RG 2758 Troubleshooting Guide
Affected components
- SAP_APPL 600 to 600
- SAP_APPL 602 to 602
- SAP_APPL 603 to 603
- SAP_APPL 604 to 604
- SAP_APPL 605 to 605
- SAP_APPL 606 to 606
- SAP_APPL 616 to 616
- SAP_APPL 617 to 617
- SAP_APPL 618 to 618
- SAPSCORE 111 to 111
- S4CORE 100 to 100
- S4CORE 101 to 101
- S4CORE 102 to 102
Full note on SAP: SAP Support Launchpad note 2519562
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
