SAP Security Note
High priority
SAP security note 1590834, "Update #1 to Security Note 1495333", is a program error note released on 21.01.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Additional correction instructions must be added for the vulnerability described in security note 1495333 (Unauthorized execution of functions in FIN-SEM BPS) due to new SAP security enhancements in the "Stateless BSP" area.
Solution
All BSP applications mentioned here or in Note 1495333 have been obsolete for several releases and must no longer be used. Since several releases, corrections are no longer delivered for these BSP applications, but this note and the preceding note 1495333 ensure that there are no currently known security threats from these BSP applications. However, these BSP applications must still not be used.
This note sets the "XSRF Protection" indicator. For more information, see Notes 1458171, 1520324, 1566128, and 1551982.
Reason and prerequisites
In security note 1495333, additional correction instructions must be added.
References
This note refers to
Affected components
- SEM-BW: Release 602 to 605
- SEM-BW: Release 634
Full note on SAP: SAP Support Launchpad note 1590834
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
