Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Aktualisierung #1 zu Sicherheitshinweis 1495333, SAP security note 1590834

SAP Note 1590834
SAP Security Note
High priority

SAP security note 1590834, "Update #1 to Security Note 1495333", is a program error note released on 21.01.2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFIN-SEM-BPS-PLA
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on21.01.2016
LanguageEnglish

Description

Symptom

Additional correction instructions must be added for the vulnerability described in security note 1495333 (Unauthorized execution of functions in FIN-SEM BPS) due to new SAP security enhancements in the "Stateless BSP" area.

Solution

All BSP applications mentioned here or in Note 1495333 have been obsolete for several releases and must no longer be used. Since several releases, corrections are no longer delivered for these BSP applications, but this note and the preceding note 1495333 ensure that there are no currently known security threats from these BSP applications. However, these BSP applications must still not be used.

This note sets the "XSRF Protection" indicator. For more information, see Notes 1458171, 1520324, 1566128, and 1551982.

Reason and prerequisites

In security note 1495333, additional correction instructions must be added.

References

Affected components

  • SEM-BW: Release 602 to 605
  • SEM-BW: Release 634

Full note on SAP: SAP Support Launchpad note 1590834

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More