Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2474 Cross-Site Request Forgery (CSRF) vulnerability in SAP Approve Leave Request V2 application, SAP security note 2696889

SAP Note 2696889SAP Security NoteMedium priority

SAP security note 2696889, "[CVE-2018-2474] Cross-Site Request Forgery (CSRF) vulnerability in SAP Approve Leave Request V2 application", is a note released on 09.10.2018. Below are the symptom and SAP recommended solution.

ComponentPersonnel Management > Fiori UI for Personal Administration > My Leave request / Approve Leave Requests
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released on09.10.2018

Description

Symptom

Unauthorized actions performed on behalf of an authenticated user.

Loss of non-repudiation.

Solution

The vulnerability is addressed by properly utilizing the XSRF protection framework, ensuring that correct authentication tokens are present. Implement the specified Support Packages and Patches referenced in this SAP Note.

CVSS

Score 4.3 / 10 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2696889

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More