Description
This note describes new switchable authorization checks for RFC function modules in IPC.
SAP Internet Pricing and Configurator (IPC), Version AP 7.00 and higher does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of missing authorization check are
- abuse functionality restricted to a particular user group
- read, modify or delete restricted data
Available fix and Supported packages
- SAP_AP | 700 | 700
- SAP_AP | 750 | 750
- SAPAPIPCJ | 700 | 700
- SAP_AP 700 | SAPKNA7035 |
- SAP_AP 750 | SAPK-75004INSAPAP |
- SAP AP IPC JAVA 7.00 | SP025 | 000147
- SAP AP IPC JAVA 7.00 | SP026 | 000142
- SAP AP IPC JAVA 7.00 | SP027 | 000132
- SAP AP IPC JAVA 7.00 | SP028 | 000112
- SAP AP IPC JAVA 7.00 | SP029 | 000096
- SAP AP IPC JAVA 7.00 | SP030 | 000092
- SAP AP IPC JAVA 7.00 | SP031 | 000075
- SAP AP IPC JAVA 7.00 | SP032 | 000062
- SAP AP IPC JAVA 7.00 | SP033 | 000041
- SAP AP IPC JAVA 7.00 | SP034 | 000025
- SAP AP IPC JAVA 7.00 | SP035 | 000000
Affected component
- AP-PRC-PR
Pricing
CVSS
Score: 7.1
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2393937