Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Switchable authorization checks for RFC in PSM-GPR, SAP security note 2030657

Description

This SAP note describes new switchable authorization checks for RFC function modules in PSM-GPR.

Available fix and Supported packages

  • SAP_APPL | 600 | 600
  • SAP_APPL | 602 | 602
  • SAP_APPL | 603 | 603
  • SAP_APPL | 604 | 604
  • SAP_APPL | 605 | 605
  • SAP_APPL | 606 | 606
  • SAP_APPL | 616 | 616
  • SAP_APPL | 617 | 617
  • EA-PS | 600 | 600
  • EA-PS | 603 | 603
  • EA-PS | 604 | 604
  • EA-PS | 605 | 605
  • EA-PS | 606 | 606
  • EA-PS | 616 | 616
  • EA-PS | 617 | 617
  • SAP_APPL 600 | SAPKH60027 |
  • SAP_APPL 602 | SAPKH60217 |
  • SAP_APPL 603 | SAPKH60316 |
  • SAP_APPL 604 | SAPKH60417 |
  • SAP_APPL 605 | SAPKH60514 |
  • SAP_APPL 606 | SAPKH60614 |
  • SAP_APPL 616 | SAPKH61609 |
  • SAP_APPL 617 | SAPKH61707 |
  • EA-PS 600 | SAPKGPPD26 |
  • EA-PS 604 | SAPK-60416INEAPS |
  • EA-PS 605 | SAPK-60513INEAPS |
  • EA-PS 606 | SAPK-60613INEAPS |
  • EA-PS 616 | SAPK-61608INEAPS |
  • EA-PS 617 | SAPK-61706INEAPS |
  • EA-PS 600 | SAPKGPPD27 |
  • EA-PS 603 | SAPK-60316INEAPS |
  • EA-PS 604 | SAPK-60417INEAPS |
  • EA-PS 605 | SAPK-60514INEAPS |
  • EA-PS 606 | SAPK-60614INEAPS |
  • EA-PS 616 | SAPK-61609INEAPS |

Affected component

    PSM-GPR
    Procurement for Public Sector

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/2030657

TAGS

#RFC
#authorization
#Procurement-for-Public-Sector
#PSM-GPR

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,