SAP Security Note
High priority
SAP security note 1516872, "Unauthorized usage of application functionality in TC@NET", is a program error note released on 10.06.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can trigger functionality in TC@NET without authentication and authorization.
Solution
- Prerequisite: Implement the corrections from SAP Note 1520324 as they are required before applying this note.
- Apply Correction Instructions: Follow the correction instructions provided in this note to implement the necessary security measures. This will create relevant reports in your system depending on your release version.
- Execute the Report: Run the provided report and specify a transport request number when prompted. The report will update the BSPTEMPXSRFSTORE database table with necessary entries for the adapted BSP applications.
Reason and prerequisites
TC@NET executes certain functions via specific URLs. An attacker can trick an authenticated user’s browser into making requests with these URLs and parameters, executing functions with the user’s privileges. This can be achieved through Cross Site Scripting attacks or by presenting clickable links to the victim.
References
- ASU content for activating XSRF protection for BSP (1540729)
- Advance creation of XSRF information (1520324)
Full note on SAP: SAP Support Launchpad note 1516872
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




