Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

KM UI vulnerable to CSRF attacks, SAP security note 1620044

SAP Note 1620044
SAP Security Note
High priority

SAP security note 1620044, "KM UI vulnerable to CSRF attacks", is a note released on February 14, 2012. Below are the symptom, SAP recommended solution and reason and prerequisites.

ComponentEnterprise Portal – Knowledge Management and Collaboration > Content Management > CM User Interface
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onFebruary 14, 2012

Description

Symptom

A malicious user can execute functions in KM UI without authentication and authorization.

Solution

Refer to the Support Package patch level section of this SAP note for details. Important: before applying this note, ensure that the following notes are already applied: 1129816 and 1450166.

Reason and prerequisites

KM UI executes certain functions by referencing specific URLs or via POST requests. When a malicious user tricks an authenticated user’s browser into making a request containing certain URLs or executing a POST request with specific parameters, the function is executed with the rights of the authenticated user. This can be achieved through cross-site scripting (XSS) attacks or by presenting a link to the victim.

References

Full note on SAP: SAP Support Launchpad note 1620044

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More