Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Request Forgery (CSRF) vulnerability in BICS InA Interface, SAP security note 2733972

SAP Note 2733972

SAP security note 2733972, "Cross-Site Request Forgery (CSRF) vulnerability in BICS InA Interface". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

BICS InA Interface allows an attacker to trick an authenticated user into sending unintended requests to the web server. This vulnerability is due to insufficient CSRF protection.

Impacts:

  • Attacker could take actions on behalf of an authenticated user
  • Loss of non-repudiation

Solution

To mitigate this vulnerability, apply the appropriate Support Package for your SAP BW system version as listed below:

Alternatively, you can use the correction instructions provided in this SAP Note. Before applying the correction instructions, ensure you review SAP Note 1668882 and SAP Note 2248091 for transaction SNOTE.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Affected components

  • BW-BEX-OT-BICS-INA

Full note on SAP: SAP Support Launchpad note 2733972

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More