Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality- SUP Portal, SAP security note 1507296

SAP Note 1507296

SAP security note 1507296, "Unauthorized usage of application functionality- SUP Portal". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can trigger functionality in Supplier Collaboration Portal without authentication and authorization.

Solution

To address this vulnerability, apply the updates available in Supplier Collaboration 4.0, which is included with SRM 7.01 SP02. Supplier Collaboration 4.0 can be accessed through the Support Package and Patch Area of the Service Marketplace.

Reason and prerequisites

The Supplier Collaboration Portal executes certain functions by referencing specific URLs. An attacker can trick an authenticated user's browser into making a request containing a specific URL and parameters, causing the function to execute with the user's privileges. Additionally, attackers might use Cross Site Scripting (XSS) attacks to exploit this vulnerability or present deceptive links to the victim.

CVSS

Score 0

References

Affected components

  • Enterprise Portal > SAP Enterprise Portal Content > SRM Packages > BP for Supplier Collaboration
  • SUP-PORTAL: Versions 2.0 and 300

Full note on SAP: SAP Support Launchpad note 1507296

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More