Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in BW-PLA-BPS, SAP security note 1554534

SAP Note 1554534

SAP security note 1554534, "Unauthorized use of application functions in BW-PLA-BPS". Below is the symptom.

Description

Symptom

A malicious user can execute functions in BW-PLA-BPS without authentication and authorization.

Reason and prerequisites

BW-PLA-BPS executes certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the rights of the authenticated user. This can be achieved through cross-site scripting attacks or by presenting a crafted link to the victim.

Full note on SAP: SAP Support Launchpad note 1554534

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More