Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in FI-AA, SAP security note 1506350

SAP Note 1506350
SAP Security Note
High priority

SAP security note 1506350, “Unauthorized usage of application functionality in FI-AA”, is a program error note released on 14.12.2010. Below are the symptom, reason and prerequisites, and the SAP recommended solution.

ComponentFinancial Accounting > Asset Accounting
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

A malicious user can execute functions without having sufficient authentication and authorization.

Solution

  • See Note 1481392 for additional information and instructions. The correction instructions contained in Note 1481392 must be implemented before you implement this note.
  • Implement the correction instructions and create the report ITS_XSRF_PARAM_FIAA_ALL in your system.
  • Execute the report ITS_XSRF_PARAM_FIAA_ALL and enter a relevant transport request when prompted. The report inserts some service parameters for the adjusted ITS services (these are usually entered by choosing the button for the GUI settings in transaction SICF for maintaining ITS services).

Reason and prerequisites

FI-AA executes certain internet services through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user.

Full note on SAP: SAP Support Launchpad note 1506350

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More