Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of FCC application functions, SAP security note 1588925

SAP Note 1588925

SAP security note 1588925, "Unauthorized use of FCC application functions". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can execute functions in the Interaction Center applications for the scenario Financial Customer Care (FCC) without authentication and authorization.

Solution

To solve this problem, perform the following manual activities.

For the BBPCRM component: call transaction SE80 in the CRM system, choose Repository Browser and select BSP Application, enter CRM_IC_FSCD, select the XSRF protection checkbox on the Properties tab, then save and activate. Repeat for CRM_IC_FICA_COH, CRM_IC_FICA_DIS, CRM_IC_FICA_FCS and CRM_IC_FICA_LCK, skipping any application not available in your release.

For the FI-CA component: call transaction SE80 in the ERP system, choose Repository Browser and select BSP Application, enter FKK_CRM_IC_F4, select the XSRF protection checkbox on the Properties tab, then save and activate.

Reason and prerequisites

The Interaction Center application for the FCC scenario executes functions when certain URLs are called. When a malicious user tricks an authenticated user's browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. The malicious user may use a cross-site scripting attack to do this, or they may present a link to the victim.

Affected components

  • BBPCRM
  • FI-CA

Full note on SAP: SAP Support Launchpad note 1588925

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More