Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of SWP services, SAP security note 1520101

SAP Note 1520101
SAP Security Note
High priority

SAP security note 1520101, "Unauthorized usage of SWP services", is a note released on June 11, 2012. Below are the symptom and SAP recommended solution.

ComponentIndustry-Specific Components > Automotive > Supplier Workplace
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released onJune 11, 2012

Description

Symptom

This security note addresses an issue where a malicious user can trigger functionalities in the Supplier Workplace (SWP) services without proper authentication and authorization. Specifically, actions can be performed without the necessary permissions on the following services:

  • ISA_SICKANBAN
  • ISA_SICALERT
  • ISAUTO_SICRPM
  • ISAUTO_SICBC
  • ISAUTO_SICASN1
  • ISAUTO_SICASN2
  • ISAUTO_SICASN3
  • ISAUTO_SICASN4
  • ISAUTO_SICCO
  • ISAUTO_SICENG
  • ISAUTO_SICDDL1
  • ISAUTO_SICJIT
  • ISAUTO_SICPDI
  • ISAUTO_SICPH
  • ISAUTO_SICPI
  • ISAUTO_SICRL
  • ISAUTO_SICRLRD
  • ISIPI_CS
  • ISIPI_CP
  • ISIPI_ESP
  • ISIPI_OEPM
  • ISIPI_PUL
  • ISIPI_SUMJIT
  • ISIPI_TRACK
  • ISIPI_SM
  • ISIPI_POD
  • ISAUTO_SIC
  • ISIPI_CE

Solution

Manual Steps for Customers on EHP5 Release:

  1. Start Transaction SICF.
  2. For each affected service: enter the service name and execute SICF to locate the service under /sap/bc/gui/sap/its/<service>. Double-click on the service name in the tree and switch to change mode. Choose the GUI configuration. Add the parameter ~XSRFCHECK with value 1. Save the settings.

Additional Steps:

  1. Refer to SAP Note 1481392 for more information and instructions. Implementing the corrections from this note is a prerequisite.
  2. Follow the correction instructions in this note, which will create the report ITS_XSRF_PARAM_604 in your system.
  3. Execute the report ITS_XSRF_PARAM_604 and provide a corresponding transport request number when prompted. This report will add service parameters for the adapted ITS services.

Note: The report name may vary based on the release (e.g., ITS_XSRF_PARAM_<release_number>).

Reason and prerequisites

Attackers can exploit this vulnerability by tricking an authenticated user’s browser into making a request with specific URLs and parameters. This can be achieved through methods like Cross-Site Scripting (XSS) attacks or by presenting clickable links to victims.

References

This note refers to

  • 1727640 – Update 1 to security note 1520101

Full note on SAP: SAP Support Launchpad note 1520101

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More