SAP security note 1973081, "XSRF vulnerability: External start of transactions with OKCode". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can trick a victim user to execute an SAP GUI shortcut (SAP GUI for Windows), a Java start transaction (SAP GUI for Java) or to click the link (SAP GUI for HTML) and execute a state-changing action in the system with the credentials of the victim.
Solution
With this SAP Note we introduce switchable white lists to enable administrators to implement XSRF protection across the input channels. The white list mechanism is implemented in SAP backend and may replace input channel specific solutions.
White listing is available in NetWeaver 740 SP08 and for releases 700 to 731 by SAP Note 2055468, for documentation refer to SAP Note 1956086.
Further on, a learning mode assists administrators to maintain white lists, for details refer to SAP Notes 1919573 (implementation) and 1922712 (documentation).
Reason and prerequisites
The XSRF protection for BSP provided by SAP Notes 1458171 and 1520324, and ITS provided by SAP Note 1481392 shall be implemented. A generic solution is required and provided by this SAP Note in the solution area.
CVSS
Score 0
References
Affected components
- BC-ABA-SC (valid from 05.01.2016)
Full note on SAP: SAP Support Launchpad note 1973081
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




