Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Request Forgery (CSRF) vulnerability in Electronic Ledger Management for Turkey 1.0, SAP security note 2367269

SAP Note 2367269
SAP Security Note
High priority

SAP security note 2367269, “Cross-Site Request Forgery (CSRF) vulnerability in Electronic Ledger Management for Turkey 1.0”, is a program error note released on 12.09.2017. Below are the symptom and the SAP recommended solution.

ComponentXX-PROJ-CDP-354
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on12.09.2017
LanguageEnglish

Description

Symptom

Electronic Ledger Management for Turkey 1.0 allows an attacker to trick an authenticated user into sending unintended requests to the web server. This vulnerability arises from insufficient CSRF protection.

Impacts of CSRF vulnerability include:

  • Actions taken on behalf of an authenticated user.
  • Loss of non-repudiation.

Solution

Download and deploy the necessary patches using the Software Upgrade Manager (SUM):

  • Navigate to Software Downloads > Software Downloads > By Alphabetical Index (A-Z) > E > ELECTRONIC LEDGER > ELECTRONIC LEDGER 1.0 > Comprised Software Component Versions > ELECTRONIC LEDGER 1.0 > #OS independent.
  • Download the patches for the service package specified in the Support Packages & Patches section of this SAP Note.
  • Deploy the patches using Software Upgrade Manager (SUM).

Reason and prerequisites

Electronic Ledger Management for Turkey 1.0 was installed following the instructions described in SAP Note 1870871.

CVSS

Score 7.6 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L

Full note on SAP: SAP Support Launchpad note 2367269

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More