Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Sales Assistant Security Note for XSRF and BSP Applications, SAP security note 1508913

SAP Note 1508913

SAP security note 1508913, "Sales Assistant: Security Note for XSRF and BSP Applications". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can trigger functionality in the BSP applications of the Portal Role "Sales Assistant" without authentication and authorization. The affected BSP applications are:

  • SLS_ASSISTANT (Role: ERP sales assistant for portal)
  • SLS_WORKLIST (Worklist for SalesRoles)
  • SLS_PROTECT (Helper Page)

Solution

Refer to SAP Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note. Implement the correction instructions of this note (1508913).

Only relevant for SAP_APPL release 604 and below:

  • Create the report BSP_XSRF_PARAM_SD as a local object in your system.
  • Execute the report BSP_XSRF_PARAM_SD and specify a transport request number when prompted. This report will populate the database table BSPTEMPXSRFSTORE with entries for the adapted BSP applications.

Reason and prerequisites

The three BSP applications of the Sales Assistant role execute certain functions by referencing specific URLs. An attacker can trick an authenticated user’s browser into making a request with a malicious URL and parameters, executing the function with the user’s rights. Potential attack approaches include:

  • Cross-Site Scripting (XSS) to trigger the exploit.
  • Phishing links prompting the victim to click.

References

Affected components

  • SAP_APPL 500 to 605

Full note on SAP: SAP Support Launchpad note 1508913

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More