SAP security note 1505302, “Purchasing Agent: Security Note for XSRF and BSP Applications”, is a note. Below are the symptom, reason and prerequisites, SAP recommended solution, references and the affected software components.
Description
Symptom
A malicious user can trigger functionality in the BSP applications of the Portal Role “Purchasing Agent” without authentication and authorization. This role is part of the business package “External Procurement”. The affected BSP applications are:
MMPUR_DOCTRK(Document Tracing)MMPUR_VNDCNF(Vendor Confirmations)
Solution
- Refer to SAP Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing this security note.
- Implement the correction instructions from this note. This will create the report
BSP_XSRF_PARAM_MM_PURin your system. - Execute the report
BSP_XSRF_PARAM_MM_PURand provide a corresponding transport request number when prompted. The report will populate the database tableBSPTEMPXSRFSTOREwith the necessary entries for the adapted BSP applications.
Reason and prerequisites
The two BSP applications execute specific functions through referencing particular URLs. An attacker could trick an authenticated user’s browser into making a request containing these URLs and specific parameters, causing the function to execute with the user’s rights. Additionally, if present, the attacker might use a Cross-Site Scripting (XSS) attack to facilitate this exploit or present a clickable link to the victim.
References
- SAP Note 1520324 – Advance creation of XSRF information
- SAP Note 1540729 – ASU content for activating XSRF protection for BSP
Affected components
- SAP_APPL (500 to 605)
Full note on SAP: SAP Support Launchpad note 1505302
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
