SAP security note 1638256, “Unauth. usage of functions in SAF compilation application”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in SAF BSP compilation applications without authentication and authorization.
Solution
- Refer to Note 1520324 and Note 1551982 for additional information and instructions. The corrections from these notes are prerequisites for implementing this note.
- Implement the correction instructions of this note. This will create the report BSP_XSRF_PARAM_CRM_EI (for CRM 5.0 and higher) or BSP_XSRF_PARAM_CRM_EI_2 (for CRM 4.0) in your system. Please note that there is a manual pre-installation instruction for CRM 4.0 that needs to be executed.
- Execute the report BSP_XSRF_PARAM_CRM_EI or BSP_XSRF_PARAM_CRM_EI_2 and specify a corresponding transport request number when prompted. The report will activate the XSRF protection for the BSP applications adapted by this note.
Reason and prerequisites
SAF BSP application executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user. If present, the attacker may use a Cross Site Request Forgery attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.
Affected components
- SAP_ABA: 700
- BBPCRM: 400
- WEBCUIF: 700, 701, 730, 731, 746
Full note on SAP: SAP Support Launchpad note 1638256
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
