SAP Security Note
High priority
SAP security note 1518807, "Unauthorized use of functions in WEB_PRICAT", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can execute functions in WEB_PRICAT without the relevant authentication and authorization.
Solution
- Implement the correction instructions or import the specified Support Package. For additional information and instructions, see Note 1481392. The corrections from Note 1481392 are a prerequisite for implementing this note.
- Implement the correction instructions provided in this note. These create the report ITS_XSRF_PARAM_WEB_PRICAT.
- Execute the report ITS_XSRF_PARAM_WEB_PRICAT and when requested, specify a relevant transport request number. The report will add service parameters for the service WEB_PRICAT (maintained using the GUI configuration pushbutton for a service within transaction SICF).
Reason and prerequisites
WEB_PRICAT executes certain functions by referencing specific URLs with parameters. When a malicious user tricks an authenticated user’s browser into making a request, the functions in WEB_PRICAT are executed with the rights of the authenticated user. The malicious user may exploit a cross-site scripting vulnerability to do this, or they may present a special link to the victim, in the form of an email, for example.
References
Affected components
- EA-RETAIL: versions 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1518807
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




