Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in ARL, SAP security note 1510672

SAP Note 1510672
SAP Security Note
High priority

SAP security note 1510672, “Unauthorized usage of application functionality in ARL”, is a program error note released on 14.12.2010. Below are the symptom, reason and prerequisites, and the SAP recommended solution.

ComponentBasis Services/Communication Interfaces > ArchiveLink (BC-SRV-ARL)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on14.12.2010

Description

Symptom

A malicious user can trigger functionality in BC-SRV-ARL without authentication and authorization.

Solution

  • Refer to Note 1481392 for additional information and instructions. The corrections from note 1481392 are a prerequisite for the implementation of this note.
  • Implement the correction instructions of this note. This will also create the report ITS_XSRF_PARAM_ARL in your system.
  • Execute the report ITS_XSRF_PARAM_ARL and specify a corresponding transport request number when prompted. The report will add service parameters for the adapted ITS services (maintained via the GUI configuration pushbutton for a service within transaction SICF).

Reason and prerequisites

Archivelink executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user. If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.

Full note on SAP: SAP Support Launchpad note 1510672

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More