SAP Security Note
High priority
SAP security note 1556749, “Unauthorized execution of functions in SAP system”, is a program error note released on April 12, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A vulnerability exists in SAP Business Workflow that allows a malicious user to execute functions in the SAP system without proper authentication and authorization. This can be exploited by tricking an authenticated user into making a specific URL request, potentially through cross-site scripting attacks or deceptive links.
Solution
Implement the correction instructions detailed in this note, regardless of whether you are using SAP Business Workflow.
Reason and prerequisites
SAP Business Workflow executes certain functions by referencing specific URLs. A malicious user can exploit this by inducing an authenticated user’s browser to make a request containing a crafted URL with specific parameters, leading to unauthorized function execution. This can be achieved through cross-site scripting attacks or by presenting deceptive links to the victim.
CVSS
Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
References
- Automatic checks for security notes using RSECNOTE (outdated)
- SAP Note 1160101 – WF Notif: Incorr logon language in SAP shortcut (LINK2)
Full note on SAP: SAP Support Launchpad note 1556749
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
