Medium priority
SAP security note 1467896, "Unauthorized use of application functions in ICM", released on 10.05.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can execute functions in the Internet Communication Manager (ICM) without proper authentication and authorization.
Solution
To mitigate this vulnerability, apply the necessary ICM patches as detailed in the “SP patch level” section of the SAP Security Note. Ensure that your ICM is updated to the specified patch levels or higher.
Reason and prerequisites
ICM executes certain functions by referencing specific URLs. A malicious user can trick an authenticated user’s browser into making a request containing a particular URL and specific parameters. This causes the function to execute with the privileges of the authenticated user. To successfully carry out this attack, the malicious user must meet special requirements, such as performing a cross-site scripting (XSS) attack or presenting a deceptive link to the victim.
CVSS
Score 0
Full note on SAP: SAP Support Launchpad note 1467896
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
