SAP security note 2507798, "Bypass of Email Verification in E-Recruiting", is a program error note released on 28.09.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
UPDATE 28th September 2017: This security note has been re-released with updated correction instructions.
When a user registers for the e-recruiting application, they receive a link via email to confirm access to the provided email address. However, this measure can be bypassed, allowing attackers to register and confirm email addresses without having access to them.
Solution
Authorization has been added to ensure that a valid user is executing the confirmation link. Please implement the attached correction instructions.
Reason and prerequisites
This vulnerability exists only when the switch RECFA_VERIF is activated.
CVSS
Score 6.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Full note on SAP: SAP Support Launchpad note 2507798
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
