SAP security note 1510064, "Unauthorized usage of appl. functionality in PA-EC,PA-CP", was released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in PA-EC and PA-CP without proper authentication and authorization. This vulnerability involves Cross-Site Request Forgery (XSRF), allowing attackers to execute certain functions by tricking an authenticated user's browser into making unauthorized requests.
Solution
The correction is delivered with a Support Package. To address this issue:
- Refer to SAP Note 1520324 for additional information and prerequisites. The corrections from this note are required before implementing this note.
- Follow the correction instructions in this note to create and execute the necessary reports and updates in your system.
References
- SAP Note 1540729: ASU content for activating XSRF protection for BSP
- SAP Note 1520324: Advance creation of XSRF information
- SAP Note 1458171: Cross-site request forgery protection for BSP
Affected components
- EA-HRGXX (Versions 110, 200, 500, 600, 602, 603, 604, 605)
Full note on SAP: SAP Support Launchpad note 1510064
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
