SAP Security Note
High priority
SAP security note 1526068, “XSRF JAVA : MSS FIN”, released on 14.12.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can trigger functionality of Business Package BP MSS 60.1 (part: My Budget) without authentication and authorization.
Solution
It is recommended not to use specific iViews and HTMLB Java pages of the Business Package BP MSS 60.1 (part: My Budget) due to the mentioned security risks. This Business Package is part of ERP 2004, which is based on HTMLB/Java. You are instructed to delete the corresponding iViews as described below. Consequently, all Portal Objects linked to these iViews must also be adapted by removing existing links to the deleted iViews.
Steps to delete delivered iViews:
- Navigate to your Portal Content Administration.
- Delete the following delivered iViews found in your Portal Content Directory under: Portal-Content / Migrated Content / EP 5.0 / iViews / Manager Self-Service: My Budget (Folder ID: pcd:portal_content/com.sap.portal.migrated/ep_5.0/iviews/Manager Self-Service: My Budget).
Customer Defined iViews: if you have defined custom iViews based on the following HTMLB pages, it is recommended to delete those iViews as well. Identify your corresponding iViews by checking the Code Link attribute.
- com.sap.pct.fin.iaainout.default
- com.sap.pct.fin.appropriationrequest.default
- com.sap.pct.fin.assetcockpit.default
- … and others as listed in the solution section.
Documentation for deletion of iViews: refer to the SAP NetWeaver Library 2004 under Portal -> Administration Guide -> Content Administration -> Portal Content Studio -> Portal Catalogue -> Managing Objects in the Portal Catalogue -> Deleting a Folder or Object, see SAP Support.
Reason and prerequisites
BP MSS 60.1 executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the user’s rights. If present, the attacker may use a Cross Site Scripting (XSS) attack to trigger the exploit or use an approach where a clickable link is presented to the victim.
Full note on SAP: SAP Support Launchpad note 1526068
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



