SAP Security Note
High priority
SAP security note 1495333, "Unauthorized execution of functions in FIN-SEM BPS", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can execute functions in the "Strategic Enterprise Management (SEM) and Business Planning & Simulation (BPS)" application without proper authentication and authorization. This vulnerability involves Cross Site Request Forgery (XSRF), where an attacker can manipulate a logged-on user’s browser to execute unauthorized queries. Methods include exploiting cross-site scripting issues or sending specifically crafted links (e.g., via email) to the user.
Solution
Implement the attached program corrections provided in the security note. Ensure that all relevant support packages are applied to mitigate the vulnerability.
References
Affected components
- Financials > Strategic Enterprise Management > Business Planning and Simulation > Planning Applications (SEM-BW-PLA)
- Supported versions: 350, 400, 600, 602, 603, 604, 605, 634, 700
Full note on SAP: SAP Support Launchpad note 1495333
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
