Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in EA-HR, SAP security note 1514483

SAP Note 1514483

SAP security note 1514483, "Unauthorized usage of application functionality in EA-HR", is a note. Below are the symptom, SAP recommended solution and the affected software components.

ComponentPA-AS (Personnel Management > HR Processes & Forms)

Description

Symptom

A malicious user can trigger functionality in EA-HR without authentication and authorization.

Solution

  • Refer to Note 1481392 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.
  • Implement the correction instructions of this note. This will also create the report RH_XSRF_PARAM_EA_HR_ITS (or RH_XSRF_PARAM_EAHR_ITS in Release 500) in your system.
  • Execute the report in the development system and specify a corresponding transport request number when prompted. The report will add service parameters for the adapted ITS services (maintained via the GUI configuration pushbutton for a service within transaction SICF).

Reason and prerequisites

EA-HR executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user.

If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.

CVSS

Score 0

References

Affected components

  • PA-AS (Personnel Management > HR Processes & Forms)
  • EA-HRGXX versions 500, 600, 602, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1514483

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More