Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in SNC, SAP security note 1511751

SAP Note 1511751
SAP Security Note
High priority

SAP security note 1511751, "Unauthorized usage of application functionality in SNC", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSupply Chain Management > SCM Basis > UI Framework
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

A malicious user can trigger functionality in SNC without authentication and authorization.

Solution

Perform the attached manual corrections.

Reason and prerequisites

SNC executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user. If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.

References

Affected components

  • SCMSNC versions 510, 700, 701
  • SCM_BASIS versions 410, 500

Full note on SAP: SAP Support Launchpad note 1511751

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More