Missing authorization check in VIRSA and VIRSANH, SAP security note 1690942
Description
An authenticated user can use functions of VIRSA and VIRSANH to which access should be restricted. This may result in an escalation of privileges
Available fix and Supported packages
- VIRSA | 400_46C | 400_46C
- VIRSA | 400_620 | 400_620
- VIRSA | 400_640 | 400_640
- VIRSA | 400_700 | 400_700
- VIRSANH | 400_46C | 400_46C
- VIRSANH | 400_620 | 400_620
- VIRSANH | 400_640 | 400_640
- VIRSANH | 400_700 | 400_700
- VIRSANH | 520_46C | 520_46C
- VIRSANH | 520_620 | 520_620
- VIRSANH | 520_640 | 520_640
- VIRSANH | 520_700 | 520_700
- VIRSANH | 530_46C | 530_46C
- VIRSANH | 530_620 | 530_620
- VIRSANH | 530_640 | 530_640
- VIRSANH | 530_700 | 530_700
- VIRSANH | 530_710 | 530_710
- VIRSANH | 530_731 | 530_731
- GRCPINW | V1000_46C | V1000_46C
- GRCPINW | V1000_620 | V1000_620
- VIRSA 400_46C | SAPK-V4C20INVIRSA |
- VIRSA 400_620 | SAPK-V4719INVIRSA |
- VIRSA 400_640 | SAPK-V4E20INVIRSA |
- VIRSA 400_700 | SAPK-47013INVIRSA |
- VIRSANH 520_46C | SAPK-52016INVIRSANH |
- VIRSANH 520_620 | SAPK-52117INVIRSANH |
- VIRSANH 520_640 | SAPK-52217INVIRSANH |
- VIRSANH 520_700 | SAPK-52317INVIRSANH |
- VIRSANH 400_46C | SAPK-40012INVIRSANH |
- VIRSANH 400_620 | SAPK-40112INVIRSANH |
- VIRSANH 400_640 | SAPK-40212INVIRSANH |
- VIRSANH 400_700 | SAPK-40313INVIRSANH |
- VIRSANH 530_620 | SAPK-53120INVIRSANH |
- VIRSANH 530_46C | SAPK-53020INVIRSANH |
- VIRSANH 530_640 | SAPK-53220INVIRSANH |
- VIRSANH 530_700 | SAPK-53320INVIRSANH |
- VIRSANH 530_710 | SAPK-53414INVIRSANH |
- VIRSANH 530_731 | 530_731 |
- GRCPINW V1000_620 | SAPK-10109INGRCPINW |
- GRCPINW V1000_640 | SAPK-10209INGRCPINW |
Affected component
- GRC-SAC-EAM
Emergency Access Management
CVSS
Score: 0
Exploit
Exploit is not available.
For detailed information please contact the mail [email protected]
URL
https://launchpad.support.sap.com/#/notes/1690942