Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

WTY, A&D XSRF Protection for BSP Application, SAP security note 1515145

SAP Note 1515145
SAP Security Note
High priority

SAP security note 1515145, "WTY, A&D: XSRF Protection for BSP Application", is a note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentIndustry-Specific Components > Automotive > Dealer Portal (IS-A-DP)
PriorityHigh priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

The XSRF protection provided by the BSP Framework is not adapted to the WTY and A&D dealer portals, which are BSP applications.

Solution

Implement the corrections attached to this note. These corrections are valid for releases up to Ehp4 (604 for EA-APPL). For Ehp5 (605 for EA-APPL) and higher, the corrections are not applicable as XSRF protection is enabled via the Workbench.

  • Refer to SAP Note 1520324 for additional information and prerequisites. The corrections from this note are required before implementing SAP Note 1515145.
  • Follow the correction instructions provided in this note. This will create the report /SAPDII/BSP_XSRF_PARAM_DII_WTY in your system.
  • Execute the report /SAPDII/BSP_XSRF_PARAM_DII_WTY and specify a transport request number when prompted. The report will populate the BSPTEMPXSRFSTORE database table with entries for the adapted BSP applications.

Reason and prerequisites

The Warranty Dealer Portal and A&D Spare Parts portal execute certain functions by referencing specific URLs. An attacker can trick an authenticated user’s browser into making requests containing specific URLs and parameters, causing functions to execute with the user’s privileges. Potential attack vectors include Cross Site Scripting (XSS) attacks or presenting clickable links to victims.

References

Affected components

  • EA-APPL versions 600, 602, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1515145

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More