SAP security note 1443934, "Security fix for event determination program", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability exists in the SRM tool for determining event customizing within the SAP Supplier Relationship Management (SAP SRM) solution. This flaw allows potential attackers to access restricted SAP transactions at runtime, which can lead to:
1. Manipulation of Business Logic: Causing inconsistent data states.
2. Violation of Regulatory Compliance: Granting unprivileged access to critical business logic.
Solution
Implement the provided corrections to address the vulnerability by replacing the generic conditions used in the customizing access program.
References
This note refers to
Affected components
- SAP SRM 6.0
- SAP SRM 7.0
Full note on SAP: SAP Support Launchpad note 1443934
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
