Missing Authorization check in SAP ERP Defence Forces and Public Security
Impact on Business
Successful attack can lead to discovery assignment between storage location and warehouse number.
Vulnerability Details
The /ISDFPS/ISDFPS/WM_LES function group, inside the /ISDFPS/MM package, implements a remote-enabled function module called /ISDFPS/GET_LGNUM_RFC which does not make any authorization check. Any user with enough privileges to call functions by RFC protocol will be able to read entries in table T320.
Solution
SAP has released SAP Note 3196280 which provides patched versions of the affected components.
The patches can be downloaded from https://launchpad.support.sap.com/#/notes/3196280.
Onapsis strongly recommends SAP customers to download the related security fixes and apply them to the affected components in order to reduce business risks.
Report Timeline
- 04/13/2022: Onapsis sends details to SAP
- 07/12/2022: SAP releases SAP Note fixing the issue.
References
Advisory Information
- Public Release Date: 08/22/25
- Security Advisory ID: ONAPSIS-2024-0025
- Researcher(s): Yvan Genuer
Vulnerability Information
- Vendor: SAP
- Affected Components:
- SAP Enterprise Extension Defense Forces & Public Security
- EA-DFPS 605 Patch 22 and lower
- EA-DFPS 606 Patch 30 and lower
- EA-DFPS 617 Patch 25 and lower
- EA-DFPS 618 Patch 19 and lower
- EA-DFPS 802 Patch 11 and lower
- EA-DFPS 803 Patch 09 and lower
- EA-DFPS 804 Patch 07 and lower
- EA-DFPS 805 Patch 05 and lower
- EA-DFPS 806 Patch 03 and lower
(Check SAP Note 3196280 for detailed information on affected releases)
- Vulnerability Class: CWE-862
- CVSS v3 score: 4.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Risk Level: Medium
- Assigned CVE: CVE-2022-31592
- Vendor patch Information: SAP Security NOTE 3196280
About our Research Labs
Onapsis Research Labs provides the industry analysis of key security issues that impact mission-critical systems and applications.
Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth knowledge and experience to deliver technical and business-context with sound security judgment to the broader information security community.
Find all reported vulnerabilities at:
https://github.com/Onapsis/vulnerability_advisories
This advisory is licensed under a Creative Commons 4.0 BY-ND International License