Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functionality in CA-GTF-RCM, SAP security note 1588241

SAP Note 1588241

SAP security note 1588241, “Unauthorized use of application functionality in CA-GTF-RCM”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can trigger functionality in CA-GTF-RCM without proper authentication and authorization.

Solution

  • Prerequisites: refer to SAP Note 1520324 and SAP Note 1551982 for additional information and instructions. Implementing corrections from these notes is required before proceeding.
  • Implement corrections: follow the correction instructions provided in SAP Security Note 1588241.
  • Activate XSRF protection: execute the report BSP_XSRF_PARAM_CA_GTF_RCM and specify a transport request number when prompted. This will activate XSRF protection for the BSP applications affected by this note.

Reason and prerequisites

This vulnerability involves Cross Site Request Forgery (CSRF or XSRF). An attacker can trick an authenticated user's browser into making requests with specific URLs and parameters, executing functions with the user's privileges. This can be exploited through Cross Site Scripting (XSS) attacks or by presenting a malicious link to the victim.

Affected components

  • SAP_ABA 640
  • SAP_ABA 700
  • SAP_ABA 701
  • SAP_ABA 702
  • SAP_ABA 710
  • SAP_ABA 711
  • SAP_ABA 720
  • SAP_ABA 730
  • SAP_ABA 731

Full note on SAP: SAP Support Launchpad note 1588241

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More