SAP Security Note
High priority
SAP security note 1485927, "Unauthorized use of application functions in PMI", is a program error note released on 10.05.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can execute functions in the display of the process monitoring overview (PMI) without authentication and authorization.
Solution
Import a current Support Package.
Reason and prerequisites
The display of the process monitoring overview executes certain functions by referencing specific URLs with parameters. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the functions in the display of the process monitoring overview are executed with the rights of the authenticated user. The malicious user may use a cross-site scripting attack to do this, or they may present a link to the victim (in the form of an e-mail, for example).
Full note on SAP: SAP Support Launchpad note 1485927
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
