Description
In the retail method of accounting (RMA) Audit Trail applications, when you display source documents in SAP ERP, authorization checks that enable a secure access to data are missing. As a result, you can use the RMA Audit Trail to display original documents in SAP ERP even though you do not have the necessary authorizations for this transaction. As a result, the sensitivity of the original documents in SAP ERP may be lost.
Available fix and Supported packages
- EA-RETAIL | 604 | 604
- EA-RETAIL | 605 | 605
- BI_CONT | 704 | 704
- BI_CONT | 705 | 705
- EA-RETAIL 605 | SAPK-60501INEARETAIL |
- EA-RETAIL 604 | SAPK-60407INEARETAIL |
- EA-RETAIL 605 | SAPK-60502INEARETAIL |
- BI_CONT 705 | SAPK-70502INBICONT |
- BI_CONT 704 | SAPK-70408INBICONT |
Affected component
- IS-R-LG-RMA
Retail Method of Accounting
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1437224