PT-2019-5599 · Sap · Sap S/4Hana Financial Products Subledger+1
Published
2019-03-12
·
Updated
2020-08-24
·
CVE-2019-0276
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SAP Banking Services version 9.0 (FSAPPL version 5)
SAP S/4HANA Financial Products Subledger (S4FPSL) version 1
Description
The issue is related to inadequate authorization checks for authenticated users, potentially leading to escalation of privileges. This could allow a remote attacker to increase their privileges.
Recommendations
For SAP Banking Services version 9.0 (FSAPPL version 5), update the authorization checks to properly validate user privileges.
For SAP S/4HANA Financial Products Subledger (S4FPSL) version 1, ensure that all user actions are properly authorized to prevent privilege escalation.
As a temporary workaround, consider restricting access to sensitive features and functionalities in both SAP Banking Services and SAP S/4HANA Financial Products Subledger until a proper fix is applied.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Banking Services
Sap S/4Hana Financial Products Subledger