SAP Security Note
High priority
SAP security note 1588137, “Unauthorized usage of application functionality in BC-SRV-RM”, is a security note released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in BC-SRV-RM without authentication and authorization.
Solution
For the stateless BSP application:
- Refer to Notes 1520324 and 1551982 for additional information and instructions. The corrections from these notes are prerequisites.
- Implement the correction instructions of this note. This will create the report BSP_XSRF_PARAM_BC_SRV_RM.
- Execute the report BSP_XSRF_PARAM_BC_SRV_RM and specify a corresponding transport request number when prompted. This action will activate XSRF protection for the adapted BSP applications.
For the stateful BSP application:
- Refer to Note 1520324 for additional information and instructions. The corrections from this note are prerequisites.
- Implement the correction instructions of this note. This will create the report BSP_XSRF_PARAM_BC_SRV_RM.
- Execute the report BSP_XSRF_PARAM_BC_SRV_RM and specify a corresponding transport request number when prompted. This action will activate XSRF protection for the adapted BSP applications.
Reason and prerequisites
When an attacker tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function executes with the user’s rights. Potential exploitation methods include Cross Site Scripting (XSS) or presenting a malicious link to the victim.
CVSS
Score 0
Affected components
- SAP_BASIS, versions 620 to 640
- SAP_BASIS, versions 700 to 702
- SAP_BASIS, versions 710 to 730
- SAP_BASIS, version 731
Full note on SAP: SAP Support Launchpad note 1588137
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
