SAP security note 1509014, "Unauthorized usage of application functionality in PA-ER". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in PA-ER without authentication and authorization.
Solution
The correction will be delivered with a Support Package. Alternatively, you can implement the correction instructions:
- Refer to note 1520324 for additional information and instructions. The corrections from note 1520324 are a prerequisite for implementation of this note.
- Implement the correction instructions of this note. This will also create the report RCF_BSP_XSRF_PARAM_TRANSPORT in your system.
- Execute the report in your development system and specify a corresponding transport request number when prompted. The report will fill the database table BSPTEMPXSRFSTORE with corresponding table entries for the BSP applications adapted by this note.
Reason and prerequisites
PA-ER executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user.
If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.
Side effects
- SAP Note 1582202 – Data overview of process template cannot be opened
References
- SAP Note 1540729 – ASU content for activating XSRF protection for BSP
- SAP Note 1520324 – Advance creation of XSRF information
- SAP Note 1458171 – Cross-site request forgery protection for BSP
Full note on SAP: SAP Support Launchpad note 1509014
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
