PT-2019-5599 · Sap · Sap S/4Hana Financial Products Subledger+1

Published

2019-03-12

·

Updated

2020-08-24

·

CVE-2019-0276

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP Banking Services version 9.0 (FSAPPL version 5) SAP S/4HANA Financial Products Subledger (S4FPSL) version 1
Description The issue is related to inadequate authorization checks for authenticated users, potentially leading to escalation of privileges. This could allow a remote attacker to increase their privileges.
Recommendations For SAP Banking Services version 9.0 (FSAPPL version 5), update the authorization checks to properly validate user privileges. For SAP S/4HANA Financial Products Subledger (S4FPSL) version 1, ensure that all user actions are properly authorized to prevent privilege escalation. As a temporary workaround, consider restricting access to sensitive features and functionalities in both SAP Banking Services and SAP S/4HANA Financial Products Subledger until a proper fix is applied.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04649
CVE-2019-0276

Affected Products

Sap Banking Services
Sap S/4Hana Financial Products Subledger