SAP Security Note
High priority
SAP security note 1588406, "Unauthorized use of industry application functions", is a program error note released on 12.07.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Unauthorized use of application functions in the Interaction Center applications for the utilities industry and the telecommunications industry.
Solution
To solve this problem, carry out the following manual activities.
Reason and prerequisites
The Interaction Center application for the utilities industry and for the telecommunications industry executes functions when certain URLs are called. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user.
The malicious user may use a cross-site scripting attack to do this, or they may present a link to the victim.
Affected components
- BBPCRM 500
- BBPCRM 520
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
Full note on SAP: SAP Support Launchpad note 1588406
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
