SAP security note 2668681, "Cross-Site Request Forgery (CSRF) SAP vulnerability in Manage Profit Centers", is a note released on September 17, 2018. Below are the symptom and SAP recommended solution.
Description
Symptom
Unauthorized actions performed in Manage Profit Centers.
Potential manipulation of profit center data without user consent.
Solution
To mitigate this CSRF vulnerability, implement the support packages and patches referenced in this SAP Security Note.
CVSS
Score 6.3 / 10 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2668681
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
