Skip links
🔥🔥🔥 Join us for our upcoming training session at Black Hat MEA: "Securing SAP Systems: Expert Insights and Penetration Testing Techniques" 🛡️🔍

RMA Authorization check missing in RMA workbench, SAP security note 1469368

Description

Certain functions of the Retail Method of Accounting (RMA) workbench can be called even if the logged-on user does not have the required authorization for this. This can lead to an escalation of privileges.

Available fix and Supported packages

  • BI_CONT | 704 | 704
  • BI_CONT | 705 | 705
  • BI_CONT 705 | SAPK-70502INBICONT |
  • BI_CONT 704 | SAPK-70408INBICONT |

Affected component

    BW-BCT-ISR-RSL
    BW only – Retail Stock Ledger

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1469368

TAGS

#Retail-Method-of-Accounting
#RMA
#stock-ledger
#authorization
#authorization-check

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer