Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of appl. functionality in Web Request, SAP security note 1513975

SAP Note 1513975
SAP Security Note
High priority

SAP security note 1513975, "Unauthorized usage of appl. functionality in Web Request", is a note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCRM-ISE-WBF (Customer Relationship Management > Internet Service > Web Forms)
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

A malicious user can trigger functionality in CRM Web Request applications without authentication and authorization.

Solution

  • Refer to Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.
  • Implement the correction instructions of this note. This will also create the report CRM_BSP_XSRF_PARAM_WEBREQ1 in your system.
  • Execute the report CRM_BSP_XSRF_PARAM_WEBREQ1 and specify a corresponding transport request number when prompted. The report will fill the database table BSPTEMPXSRFSTORE with corresponding table entries for the BSP applications adapted by this note.

Reason and prerequisites

The BSP applications CRM_WR_SHOW_SIG, WFF_START, and CRM_BSP_WEBREQF execute certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the user’s rights.

If present, the attacker may use a Cross Site Scripting attack to trigger the exploit or present a clickable link to the victim.

CVSS

Score 0

References

This note refers to

Referenced by

Affected components

  • BBPCRM 400
  • BBPCRM 500
  • BBPCRM 520
  • BBPCRM 600
  • BBPCRM 700
  • BBPCRM 701

Full note on SAP: SAP Support Launchpad note 1513975

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More