Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized execution of functions in SAP system, SAP security note 1556749

SAP Note 1556749
SAP Security Note
High priority

SAP security note 1556749, “Unauthorized execution of functions in SAP system”, is a program error note released on April 12, 2011. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Business Management > Business Workflow > WebFlow Notifications
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released onApril 12, 2011

Description

Symptom

A vulnerability exists in SAP Business Workflow that allows a malicious user to execute functions in the SAP system without proper authentication and authorization. This can be exploited by tricking an authenticated user into making a specific URL request, potentially through cross-site scripting attacks or deceptive links.

Solution

Implement the correction instructions detailed in this note, regardless of whether you are using SAP Business Workflow.

Reason and prerequisites

SAP Business Workflow executes certain functions by referencing specific URLs. A malicious user can exploit this by inducing an authenticated user’s browser to make a request containing a crafted URL with specific parameters, leading to unauthorized function execution. This can be achieved through cross-site scripting attacks or by presenting deceptive links to the victim.

CVSS

Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

References

Full note on SAP: SAP Support Launchpad note 1556749

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More