Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of functions in WEB_PRICAT, SAP security note 1518807

SAP Note 1518807
SAP Security Note
High priority

SAP security note 1518807, "Unauthorized use of functions in WEB_PRICAT", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentLogistics – General > SAP Retail Store (LO-SRS)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onDecember 14, 2010
LanguageEnglish

Description

Symptom

A malicious user can execute functions in WEB_PRICAT without the relevant authentication and authorization.

Solution

  • Implement the correction instructions or import the specified Support Package. For additional information and instructions, see Note 1481392. The corrections from Note 1481392 are a prerequisite for implementing this note.
  • Implement the correction instructions provided in this note. These create the report ITS_XSRF_PARAM_WEB_PRICAT.
  • Execute the report ITS_XSRF_PARAM_WEB_PRICAT and when requested, specify a relevant transport request number. The report will add service parameters for the service WEB_PRICAT (maintained using the GUI configuration pushbutton for a service within transaction SICF).

Reason and prerequisites

WEB_PRICAT executes certain functions by referencing specific URLs with parameters. When a malicious user tricks an authenticated user’s browser into making a request, the functions in WEB_PRICAT are executed with the rights of the authenticated user. The malicious user may exploit a cross-site scripting vulnerability to do this, or they may present a special link to the victim, in the form of an email, for example.

References

Affected components

  • EA-RETAIL: versions 500, 600, 602, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1518807

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More