SAP Security Note
Medium priority
SAP security note 2652102, "Missing Authorization checks for Templates and Business Partner Search in Payment Engine", is a program error note released on 12.03.2019. Below are the symptom and SAP recommended solution.
Description
Symptom
Payment Engine does not perform necessary authorization checks for an authenticated user when:
- Searching Business Partner Information
- Managing Payment Order Templates
This oversight results in escalation of privileges, allowing:
- Abuse of functionality restricted to specific user groups
- Unauthorized read, modify, or delete access to restricted data
Solution
Apply the preliminary correction as per the correction instructions included in this SAP Note or via the relevant Support Package.
Reason and prerequisites
The user must be authorized to use the application.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2652102
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
