SAP security note 1511062, “Unauthorized usage of application functionality in IS-HER-CM”, is a note. Below are the symptom, reason and prerequisites, SAP recommended solution, references and the affected software components.
Description
Symptom
- Ability to execute certain functions in IS-HER-CM without authentication.
- Exploitation can occur through specific URLs and parameters.
Solution
- Refer to SAP Note 1520324 for additional information and instructions. Implementing the corrections from this note is a prerequisite for applying this note.
- Implement the correction instructions provided in this note. This will create the report
BSP_XSRF_PARAM_PMIQ_<release>in your system. - Execute the report
BSP_XSRF_PARAM_PMIQ_<release>and provide a corresponding transport request number when prompted. This will populate theBSPTEMPXSRFSTOREdatabase table with the necessary entries for the BSP applications modified by this note.
Reason and prerequisites
IS-HER-CM performs specific functions by referencing certain URLs. An attacker can trick an authenticated user’s browser into making a request with these URLs and parameters, causing the function to execute with the user’s privileges. This can be achieved via:
- Cross Site Scripting (XSS) attacks.
- Presenting malicious links to the victim.
References
This note refers to
Affected components
- IS-PS-CA (472, 600, 602, 603, 604, 605)
Full note on SAP: SAP Support Launchpad note 1511062
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



