SAP Security Note
High priority
SAP security note 1507735, "Unauthorized execution of functions in IS-Media", is a program error note released on 13.11.2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can execute functions in IS-Media without authentication and authorization.
Solution
- Import the relevant Support Package.
- If you want to implement an advanced correction up to and including IS-M 604: if you are using BSP applications, implement Note 1520324 and pay particular attention to the manual step described there; if you are using ITS applications, implement Note 1481392 and pay particular attention to the manual step described there.
- Use the Note Assistant (transaction SNOTE) to implement the corrections contained in this note.
- Manual post-implementation steps: for BSP applications, execute the report RJ_BSP_XSRF_PARAM_ISM_606; for ITS applications (IACs), execute the report RJ_ITS_XSRF_PARAM_ISM_606.
Reason and prerequisites
IS-Media executes certain functions by referencing specific URLs. When a malicious user tricks an authenticated user's browser into making a request containing a certain URL and specific parameters, the functions in IS-Media are executed with the rights of the authenticated user. The malicious user may use a cross-site scripting attack to do this, or they may present a link to the victim.
References
- 1540729: ASU content for activating XSRF protection for BSP
- 1520324: Advance creation of XSRF information
- 1481392: Cross Site Request Forgery Protection for ITS
Affected components
- IS-M 471 to 605
Full note on SAP: SAP Support Launchpad note 1507735
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
