Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

XSRF Protection for the stateless BSP application, SAP security note 1597931

SAP Note 1597931

SAP security note 1597931, “XSRF Protection for the stateless BSP application”, is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can execute functions in the SRM application without proper authentication and authorization.

Solution

Import the corresponding Support Package (SP) or follow the correction instructions provided in this note. After applying the correction instructions, follow the manual steps outlined below.

WarningPerform this manual activity separately in each system where the note is transported for implementation.

Reason and prerequisites

SRM applications execute certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the user’s rights. This can be achieved through a cross-site scripting attack or by presenting a deceptive link to the victim.

References

Affected components

  • SRM_SERVER (versions 500, 550, 600, 700, 701)

Full note on SAP: SAP Support Launchpad note 1597931

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More