SAP Security Note
SAP security note 1587581, "Unauthorized Use of Application Functions in Workflow (BSP)", is released on December 12, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can execute functions in the Business Workflow without proper authentication and authorization. This vulnerability can be exploited through cross-site request forgery (XSRF) or by tricking an authenticated user’s browser into executing specific URLs with parameters.
Unauthorized access to workflow functions may compromise business processes, data integrity, and overall system security. This can lead to unauthorized actions being performed within the workflow system, potentially affecting critical business operations.
Solution
To mitigate this vulnerability, follow these steps:
- Prerequisites: Ensure that SAP Notes 1520324 and 1551982 are implemented, as they are prerequisites for this security note.
- Implement Correction Instructions: Apply the correction instructions provided in this note. This will create the program BSP_XSRF_PARAM_BC_BMT_WFM_2 in your system.
- Activate XSRF Protection: Execute the program BSP_XSRF_PARAM_BC_BMT_WFM_2 and select the appropriate transport request when prompted. This will activate XSRF protection for the adjusted applications.
References
- Workflow notifications: Notification contains JavaScript
- Configuration of BSP application SWN_WIEXECUTE
- Cross-site request forgery protection for stateless
- Advance creation of XSRF information
- SAP Note 1956449 – WebFlow Notifications: SMS contains JavaScript
Affected components
- SAP_BASIS versions 620 to 731
Full note on SAP: SAP Support Launchpad note 1587581
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
