SAP security note 1554534, "Unauthorized use of application functions in BW-PLA-BPS". Below is the symptom.
Description
Symptom
A malicious user can execute functions in BW-PLA-BPS without authentication and authorization.
Reason and prerequisites
BW-PLA-BPS executes certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the rights of the authenticated user. This can be achieved through cross-site scripting attacks or by presenting a crafted link to the victim.
Full note on SAP: SAP Support Launchpad note 1554534
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




