Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in workflow (BSP), SAP security note 1587581

SAP Note 1587581
SAP Security Note

SAP security note 1587581, "Unauthorized Use of Application Functions in Workflow (BSP)", is released on December 12, 2013. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSAP Basis > Business Management > Business Workflow
TypeSAP Security Note
Released onDecember 12, 2013

Description

Symptom

A malicious user can execute functions in the Business Workflow without proper authentication and authorization. This vulnerability can be exploited through cross-site request forgery (XSRF) or by tricking an authenticated user’s browser into executing specific URLs with parameters.

Unauthorized access to workflow functions may compromise business processes, data integrity, and overall system security. This can lead to unauthorized actions being performed within the workflow system, potentially affecting critical business operations.

Solution

To mitigate this vulnerability, follow these steps:

  • Prerequisites: Ensure that SAP Notes 1520324 and 1551982 are implemented, as they are prerequisites for this security note.
  • Implement Correction Instructions: Apply the correction instructions provided in this note. This will create the program BSP_XSRF_PARAM_BC_BMT_WFM_2 in your system.
  • Activate XSRF Protection: Execute the program BSP_XSRF_PARAM_BC_BMT_WFM_2 and select the appropriate transport request when prompted. This will activate XSRF protection for the adjusted applications.

References

Affected components

  • SAP_BASIS versions 620 to 731

Full note on SAP: SAP Support Launchpad note 1587581

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More