SAP Security Note
High priority
SAP security note 1645146, "Certain service calls can be executed through URL", is a program error note released on 14.02.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can execute service calls in Knowledge Management (KM) without authentication and authorization.
Solution
Refer to the SP patch level section of this SAP note for detailed instructions. Important: Before applying this note, ensure that SAP Note 1620044 is already applied.
Reason and prerequisites
KM executes certain service calls by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL, the service call is executed with the rights of the authenticated user.
References
- SAP Note 1670979 – KMC in SAP NetWeaver 7.0 SPS26
- SAP Note 1620044 – KM UI vulnerable to CSRF attacks
- SAP Note 1581513 – KMC in EHP2 for SAP NetWeaver 7.02 SPS9
- SAP Note 1540495 – KMC release 7.30 SP3
- SAP Note 1514806 – KMC in EHP2 for SAP NetWeaver 7.02 SPS7
- SAP Note 1473461 – KMC in EHP1 for SAP NetWeaver 7.0 SPS8
Affected components
- Enterprise Portal > Enterprise Portal – Knowledge Management and Collaboration > Content Management > CM User Interface (EP-KM-CM-UI)
Full note on SAP: SAP Support Launchpad note 1645146
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
