Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of applic. functions in In-Store MIM Mobile, SAP security note 1589377

SAP Note 1589377
SAP Security Note
High priority

SAP security note 1589377, "Unauthorized use of applic. functions in In-Store MIM Mobile", released on 09.08.2011. Below are the symptom and SAP recommended solution.

ComponentLogistics – General > SAP Retail Store (LO-SRS)
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released on09.08.2011

Description

Symptom

A malicious user can execute functions in Mobile Inventory Management and Physical Inventory with ITSmobile (In-Store MIM Mobile) without authentication and authorization.

Issue: Cross-site request forgery (XSRF) allows malicious users to execute functions with the rights of an authenticated user by tricking their browser into making unauthorized requests.

Affected functions: Mobile Inventory Management and Physical Inventory in ITSmobile.

Solution

  • Prerequisite: apply the corrections from SAP Note 1481392 for Cross Site Request Forgery Protection for ITS.
  • Implement corrections: follow the instructions in this note to create and execute the report ITS_XSRF_PARAM_MIM_MOBILE in your system. This will add necessary service parameters for the ITS service.

References

Full note on SAP: SAP Support Launchpad note 1589377

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More