SAP Security Note
High priority
SAP security note 1514098, "Unauthorized Usage of Application Functionality", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in the following BSP applications without authentication and authorization: CARPTEST, CRM_MKTTG_SEGAP, CRM_MKTCA_UI, CRM_MKTIMEX_MON.
Solution
- Refer to Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.
- Implement the correction instructions of this note. This will create the report BSP_XSRF_PARAM_CRM_MKT in your system.
- Execute the report BSP_XSRF_PARAM_CRM_MKT and specify a corresponding transport request number when prompted. The report will populate the database table BSPTEMPXSRFSTORE with entries for the BSP applications adapted by this note.
Reason and prerequisites
The mentioned BSP applications execute certain functions by referencing specific URLs. An attacker can trick an authenticated user’s browser into making a request containing certain URLs and parameters, causing functions to execute with the user’s rights.
If present, the attacker may use a Cross Site Scripting attack to trigger the exploit or present a clickable link to the victim.
CVSS
Score 0
References
Affected components
- BBPCRM 400
- BBPCRM 500
- BBPCRM 520
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
Full note on SAP: SAP Support Launchpad note 1514098
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




