Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in PMI, SAP security note 1485927

SAP Note 1485927
SAP Security Note
High priority

SAP security note 1485927, "Unauthorized use of application functions in PMI", is a program error note released on 10.05.2011. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Basis Services/Communication Interfaces > Process Monitoring Infrastructure
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on10.05.2011
LanguageEnglish

Description

Symptom

A malicious user can execute functions in the display of the process monitoring overview (PMI) without authentication and authorization.

Solution

Import a current Support Package.

Reason and prerequisites

The display of the process monitoring overview executes certain functions by referencing specific URLs with parameters. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the functions in the display of the process monitoring overview are executed with the rights of the authenticated user. The malicious user may use a cross-site scripting attack to do this, or they may present a link to the victim (in the form of an e-mail, for example).

Full note on SAP: SAP Support Launchpad note 1485927

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More