Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security fix for user search program, SAP security note 1486835

SAP Note 1486835
SAP Security Note
Medium priority

SAP security note 1486835, "Security fix for user search program", was released on 12.10.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSupplier Relationship Management > Supplier Self-Services > Business Partner, User, Customizing (SRM-SUS-ADM)
PriorityMedium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on12.10.2010

Description

Symptom

Due to a vulnerability in the SRM-SUS tool for user determination, a part of the SAP Supplier Relationship Management (SAP SRM) solution, it is possible for a hacker to access restricted SAP transactions at runtime. This can lead to:

  • Manipulation of Business Logic, resulting in inconsistent data states
  • Violation of regulatory compliance due to unprivileged access to critical business logic.

Solution

Please implement the attached corrections.

Solution details: The generic conditions used in the customizing access program have been replaced.

Reason and prerequisites

This is a program error caused by generic access during dynamic calls to transactions from SRM programs. Malicious users controlling such transaction calls can exploit this vulnerability.

Affected components

  • SAP SRM 4.0
  • SAP SRM 5.0
  • SAP SRM 6.0
  • SAP SRM 7.0

Full note on SAP: SAP Support Launchpad note 1486835

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More