Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) performs an inadequate authorization check for an authenticated user, potentially resulting in escalation of privileges.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=515408080 | vendor advisory |
http://www.securityfocus.com/bid/107353 | vdb entry third party advisory |
https://launchpad.support.sap.com/#/notes/2754235 | permissions required vendor advisory |