Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in TC@NET, SAP security note 1516872

SAP Note 1516872
SAP Security Note
High priority

SAP security note 1516872, "Unauthorized usage of application functionality in TC@NET", is a program error note released on 10.06.2011. Below are the symptom and SAP recommended solution.

ComponentLogistics – General > Global Trade (LO-GT)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on10.06.2011

Description

Symptom

A malicious user can trigger functionality in TC@NET without authentication and authorization.

Solution

  • Prerequisite: Implement the corrections from SAP Note 1520324 as they are required before applying this note.
  • Apply Correction Instructions: Follow the correction instructions provided in this note to implement the necessary security measures. This will create relevant reports in your system depending on your release version.
  • Execute the Report: Run the provided report and specify a transport request number when prompted. The report will update the BSPTEMPXSRFSTORE database table with necessary entries for the adapted BSP applications.

Reason and prerequisites

TC@NET executes certain functions via specific URLs. An attacker can trick an authenticated user’s browser into making requests with these URLs and parameters, executing functions with the user’s privileges. This can be achieved through Cross Site Scripting attacks or by presenting clickable links to the victim.

References

Full note on SAP: SAP Support Launchpad note 1516872

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More