High priority
SAP security note 1543942, “Unauthorized use of application functions in AFP Servlet”, is a security note released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can execute functions in AFP Servlet without authentication and authorization.
Solution
Apply the appropriate support package patch from the Support Package Patches tab on the SAP Notes page.
Reason and prerequisites
This vulnerability allows unauthorized execution of specific functions within the AFP Servlet. By exploiting this, a malicious user can trick an authenticated user’s browser into making unauthorized requests, leading to potential security breaches. Techniques such as cross-site request forgery (XSRF) or presenting malicious links can be used to execute these unauthorized functions.
- Unauthorized access to application functions.
- Potential data breaches and manipulation.
- Compromise of user authentication and authorization mechanisms.
Affected components
- EP-PIN-NAV-AFP (Enterprise Portal > SAP Enterprise Portal (On-Premise) > Navigation > Ajax Framework Page), versions 7.01 to 7.02
Full note on SAP: SAP Support Launchpad note 1543942
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



