SAP security note 1734986, "Unauthorized usage of functions in SAP start service", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can execute functions in SAP start service without authentication and authorization.
Solution
Apply the kernel patch specified in this SAP Note to solve this problem. Use this kernel or a more recent kernel.
Reason and prerequisites
SAP start service executes certain functions by referencing specific URLs. When an attacker tricks an authenticated user's browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. The attacker may use a cross-site scripting attack to do this, or they may present a link to the victim.
CVSS
Score 5.8 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:P
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1734986
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




