SAP security note 1509016, "Unauthorized usage of application functionality in SAP_HR". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in SAP_HR without authentication and authorization.
Solution
The correction will be delivered with a Support Package. The relationship between the Support Package and the technical name given under "Support Packages" is described in SAP note 1232082.
Alternatively, you can implement the correction instructions:
- Refer to note 1481392 for additional information and instructions. The corrections from note 1481392 are a prerequisite for implementation of this note.
- Implement the correction instructions of this note. This will also create the report RH_XSRF_PARAM_SAP_HR_ITS in your system.
- Execute the report and specify a corresponding transport request number when prompted. The report will add service parameters for the adapted ITS services (maintained via the GUI configuration pushbutton for a service within transaction SICF).
Reason and prerequisites
SAP_HR executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user.
If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.
References
- SAP Note 1481392 – Cross Site Request Forgery Protection for ITS
Affected components
- SAP_HRGXX 500
- SAP_HRGXX 600
- SAP_HRGXX 604
Full note on SAP: SAP Support Launchpad note 1509016
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
