Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Request Forgery (CSRF) SAP vulnerability in Manage Profit Centers, SAP security note 2668681

SAP Note 2668681SAP Security NoteMedium priority

SAP security note 2668681, "Cross-Site Request Forgery (CSRF) SAP vulnerability in Manage Profit Centers", is a note released on September 17, 2018. Below are the symptom and SAP recommended solution.

ComponentControlling > Fiori UI for Overhead Cost Controlling (CO-FIO)
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released onSeptember 17, 2018
LanguageEnglish

Description

Symptom

Unauthorized actions performed in Manage Profit Centers.

Potential manipulation of profit center data without user consent.

Solution

To mitigate this CSRF vulnerability, implement the support packages and patches referenced in this SAP Security Note.

CVSS

Score 6.3 / 10 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Full note on SAP: SAP Support Launchpad note 2668681

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More