Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized execution of functions in FIN-SEM BPS, SAP security note 1495333

SAP Note 1495333
SAP Security Note
High priority

SAP security note 1495333, "Unauthorized execution of functions in FIN-SEM BPS", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFinancials > Strategic Enterprise Management > Business Planning and Simulation > Planning Applications (SEM-BW-PLA)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

An attacker can execute functions in the "Strategic Enterprise Management (SEM) and Business Planning & Simulation (BPS)" application without proper authentication and authorization. This vulnerability involves Cross Site Request Forgery (XSRF), where an attacker can manipulate a logged-on user’s browser to execute unauthorized queries. Methods include exploiting cross-site scripting issues or sending specifically crafted links (e.g., via email) to the user.

Solution

Implement the attached program corrections provided in the security note. Ensure that all relevant support packages are applied to mitigate the vulnerability.

References

Affected components

  • Financials > Strategic Enterprise Management > Business Planning and Simulation > Planning Applications (SEM-BW-PLA)
  • Supported versions: 350, 400, 600, 602, 603, 604, 605, 634, 700

Full note on SAP: SAP Support Launchpad note 1495333

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More