Skip links

Missing authorization check in VIRSA and VIRSANH, SAP security note 1690942

Description

An authenticated user can use functions of VIRSA and VIRSANH to which access should be restricted. This may result in an escalation of privileges

Available fix and Supported packages

  • VIRSA | 400_46C | 400_46C
  • VIRSA | 400_620 | 400_620
  • VIRSA | 400_640 | 400_640
  • VIRSA | 400_700 | 400_700
  • VIRSANH | 400_46C | 400_46C
  • VIRSANH | 400_620 | 400_620
  • VIRSANH | 400_640 | 400_640
  • VIRSANH | 400_700 | 400_700
  • VIRSANH | 520_46C | 520_46C
  • VIRSANH | 520_620 | 520_620
  • VIRSANH | 520_640 | 520_640
  • VIRSANH | 520_700 | 520_700
  • VIRSANH | 530_46C | 530_46C
  • VIRSANH | 530_620 | 530_620
  • VIRSANH | 530_640 | 530_640
  • VIRSANH | 530_700 | 530_700
  • VIRSANH | 530_710 | 530_710
  • VIRSANH | 530_731 | 530_731
  • GRCPINW | V1000_46C | V1000_46C
  • GRCPINW | V1000_620 | V1000_620
  • VIRSA 400_46C | SAPK-V4C20INVIRSA |
  • VIRSA 400_620 | SAPK-V4719INVIRSA |
  • VIRSA 400_640 | SAPK-V4E20INVIRSA |
  • VIRSA 400_700 | SAPK-47013INVIRSA |
  • VIRSANH 520_46C | SAPK-52016INVIRSANH |
  • VIRSANH 520_620 | SAPK-52117INVIRSANH |
  • VIRSANH 520_640 | SAPK-52217INVIRSANH |
  • VIRSANH 520_700 | SAPK-52317INVIRSANH |
  • VIRSANH 400_46C | SAPK-40012INVIRSANH |
  • VIRSANH 400_620 | SAPK-40112INVIRSANH |
  • VIRSANH 400_640 | SAPK-40212INVIRSANH |
  • VIRSANH 400_700 | SAPK-40313INVIRSANH |
  • VIRSANH 530_620 | SAPK-53120INVIRSANH |
  • VIRSANH 530_46C | SAPK-53020INVIRSANH |
  • VIRSANH 530_640 | SAPK-53220INVIRSANH |
  • VIRSANH 530_700 | SAPK-53320INVIRSANH |
  • VIRSANH 530_710 | SAPK-53414INVIRSANH |
  • VIRSANH 530_731 | 530_731 |
  • GRCPINW V1000_620 | SAPK-10109INGRCPINW |
  • GRCPINW V1000_640 | SAPK-10209INGRCPINW |

Affected component

    GRC-SAC-EAM
    Emergency Access Management

CVSS

Score: 0

Exploit

Exploit is not available.
For detailed information please contact the mail [email protected]

URL

https://launchpad.support.sap.com/#/notes/1690942

TAGS

#Authorization
#authorization-check
#VIRSA
#VIRSANH