Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori APP-Process Collection Worklist, SAP security note 2733219

SAP Note 2733219

SAP security note 2733219, "Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori APP-Process Collection Worklist". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Fiori APP-Process Collection Worklist allows an attacker to trick an authenticated user into sending unintended requests to the web server. This vulnerability is due to insufficient CSRF protection.

Impacts of CSRF Vulnerability:

  • Attacker can perform actions on behalf of an authenticated user.
  • Loss of non-repudiation.

Solution

Implement the Support Packages and Patches referenced by this SAP Note.

CVSS

Score 6.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Affected components

  • FIN-FIO-CCD (versions 200, 300, 400, 500)

Full note on SAP: SAP Support Launchpad note 2733219

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More