Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized change of contents in CERTREQ and CERTMAP, SAP security note 1417568

SAP Note 1417568

SAP security note 1417568, "Unauthorized Change of Contents in CERTREQ and CERTMAP". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can manipulate the BSP applications CERTREQ and CERTMAP to change displayed data of another user without authorization and may access the authorization data of this user.

Solution

Implement the attached corrections provided in this security note. For Release 6.40, also apply the corrections from Note 1475840 and the kernel patch from Note 1468542. If the BSP applications CERTREQ and CERTMAP are not required, deactivate them using transaction SICF. Additionally, ensure that the ITS services CERTREQ and CERTMAP are deactivated in each case.

Reason and prerequisites

Due to inadequate input validation in the BSP applications CERTREQ and CERTMAP, a reflected cross-site scripting (XSS) vulnerability can be triggered. This allows the content of a web page to be manipulated when a crafted link is accessed. An attacker can exploit this to steal the logon information of the current session, impersonate the victim, and access the application with the victim’s privileges. If the victim has administrative rights, all application data may be compromised.

References

Affected components

  • SAP_BASIS 6.40
  • SAP_BASIS 7.00 to 7.02
  • SAP_BASIS 7.10 to 7.20

Full note on SAP: SAP Support Launchpad note 1417568

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More