Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Purchasing Agent Security Note for XSRF and BSP Applicat., SAP security note 1505302

SAP Note 1505302

SAP security note 1505302, “Purchasing Agent: Security Note for XSRF and BSP Applications”, is a note. Below are the symptom, reason and prerequisites, SAP recommended solution, references and the affected software components.

Description

Symptom

A malicious user can trigger functionality in the BSP applications of the Portal Role “Purchasing Agent” without authentication and authorization. This role is part of the business package “External Procurement”. The affected BSP applications are:

  • MMPUR_DOCTRK (Document Tracing)
  • MMPUR_VNDCNF (Vendor Confirmations)

Solution

  • Refer to SAP Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing this security note.
  • Implement the correction instructions from this note. This will create the report BSP_XSRF_PARAM_MM_PUR in your system.
  • Execute the report BSP_XSRF_PARAM_MM_PUR and provide a corresponding transport request number when prompted. The report will populate the database table BSPTEMPXSRFSTORE with the necessary entries for the adapted BSP applications.

Reason and prerequisites

The two BSP applications execute specific functions through referencing particular URLs. An attacker could trick an authenticated user’s browser into making a request containing these URLs and specific parameters, causing the function to execute with the user’s rights. Additionally, if present, the attacker might use a Cross-Site Scripting (XSS) attack to facilitate this exploit or present a clickable link to the victim.

References

Affected components

  • SAP_APPL (500 to 605)

Full note on SAP: SAP Support Launchpad note 1505302

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More