SAP Security Note
High priority
SAP security note 2367269, “Cross-Site Request Forgery (CSRF) vulnerability in Electronic Ledger Management for Turkey 1.0”, is a program error note released on 12.09.2017. Below are the symptom and the SAP recommended solution.
Description
Symptom
Electronic Ledger Management for Turkey 1.0 allows an attacker to trick an authenticated user into sending unintended requests to the web server. This vulnerability arises from insufficient CSRF protection.
Impacts of CSRF vulnerability include:
- Actions taken on behalf of an authenticated user.
- Loss of non-repudiation.
Solution
Download and deploy the necessary patches using the Software Upgrade Manager (SUM):
- Navigate to Software Downloads > Software Downloads > By Alphabetical Index (A-Z) > E > ELECTRONIC LEDGER > ELECTRONIC LEDGER 1.0 > Comprised Software Component Versions > ELECTRONIC LEDGER 1.0 > #OS independent.
- Download the patches for the service package specified in the Support Packages & Patches section of this SAP Note.
- Deploy the patches using Software Upgrade Manager (SUM).
Reason and prerequisites
Electronic Ledger Management for Turkey 1.0 was installed following the instructions described in SAP Note 1870871.
CVSS
Score 7.6 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Full note on SAP: SAP Support Launchpad note 2367269
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
