Medium priority
SAP security note 2061129, "Missing whitelist check in SAP Dispute Management", is a note released on November 30, 2018. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of SAP Dispute Management to which access should be restricted. This may result in an escalation of privileges.
Solution
Implement the correction instructions provided in the SAP Security Note.
Reason and prerequisites
SAP Dispute Management while editing a dispute case does not contain required checks against a positive set of allowed functions (i.e., whitelist) during execution of these functions. This is required to verify that authenticated users are allowed to access these functions. The missing check may result in undesired system behavior.
CVSS
Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
Full note on SAP: SAP Support Launchpad note 2061129
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
