Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in SSR, SAP security note 1509638

SAP Note 1509638SAP Security NoteHigh priority

SAP security note 1509638, "Unauthorized usage of application functionality in SSR", is released on 14.12.2010. Below is the SAP recommended solution.

ComponentIS-OIL-DS-SSR
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released on14.12.2010

Description

Solution

  • Refer to SAP Note 1481392: Additional Information and Instructions Note 1481392 must be implemented as a prerequisite before applying this note.
  • Implement Correction Instructions: Download for SNOTE Following the correction instructions will create the report ITS_XSRF_PARAM_IS_OIL_SSR in your system.
  • Execute the Report: Run ITS_XSRF_PARAM_IS_OIL_SSR and specify a corresponding transport request number when prompted. This report will add the necessary service parameters for the adapted ITS services, which can be managed via the GUI configuration in transaction SICF.

Reason and prerequisites

The SAP IS-Oil Store Workbench executes certain functions by referencing specific URLs. An attacker can trick an authenticated user's browser into making a request containing a particular URL and specific parameters, causing the function to execute with the user's permissions. Potential attack vectors include Cross-Site Scripting (XSS) or presenting a deceptive link for the victim to click.

Full note on SAP: SAP Support Launchpad note 1509638

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More