SAP security note 1589707, "Unauthorized execution of functions in agency collections", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can execute Italian FS-CD agency collection functions without the required authentication and authorization.
Important: this note is only relevant for customers who use FS-CD (software component INSURANCE) and the Italian agency collections (BSP application ITAGCY, activated using transaction ITAGCYCUST, Basic Settings, Basic settings for agency collections). Other customers are not affected and do not have to implement this note.
Solution
Implement the attached program corrections. For releases lower than INSURANCE 6.05, follow the instructions below.
The described solution will not resolve the issue if you are using BSP design DESIGN2002. You can use the user parameter ID ITAGCY_DESIGN to set up the design for the Italian agency collections individually for each user. Alternatively, you can use the BSP application ITAGCY_USERDATA, where the user can manually change the design.
Also see Note 1509885 for BSP design DESIGN2008.
- For further information and instructions, refer to Notes 1520324 and 1551982. Before implementing this note, you must first apply the corrections from Notes 1520324 and 1551982. (Applies to releases INSURANCE below 6.05.)
- Implement the correction instructions relevant to your release as detailed in this note. This will create or modify the report BSP_XSRF_PARAM_FSCD in your system.
- Execute the report BSP_XSRF_PARAM_FSCD and, when prompted, specify a relevant transport request number. The report updates the policy configurations of the BSP applications for agency collections.
Reason and prerequisites
The BSP application for the Italian agency collections executes functions by calling certain URLs with parameters. If a malicious user succeeds in executing requests through the browser of a logged-in user, the malicious user can call functions with the rights of the user.
To achieve this, a malicious user can exploit a potential vulnerability in cross-site scripting or send the user a specially crafted link, for example via email.
References
This note refers to
Affected components
- INSURANCE
Full note on SAP: SAP Support Launchpad note 1589707
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
