SAP security note 2696889, "[CVE-2018-2474] Cross-Site Request Forgery (CSRF) vulnerability in SAP Approve Leave Request V2 application", is a note released on 09.10.2018. Below are the symptom and SAP recommended solution.
Description
Symptom
Unauthorized actions performed on behalf of an authenticated user.
Loss of non-repudiation.
Solution
The vulnerability is addressed by properly utilizing the XSRF protection framework, ensuring that correct authentication tokens are present. Implement the specified Support Packages and Patches referenced in this SAP Note.
CVSS
Score 4.3 / 10 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2696889
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



