Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification in ITS-Services of ISR, SAP security note 1674219

SAP Note 1674219
SAP Security Note
High Priority

SAP security note 1674219, "Unauthorized Modification in ITS-Services of ISR", is a note released on May 8, 2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentControlling > Overhead Cost Controlling (CO-OM); Controlling > Overhead Cost Controlling > Cost Center Accounting (CO-OM-CCA); Financial Accounting > General Ledger Accounting (FI-GL); Quality Management (QM)
PriorityCorrection with High Priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released onMay 8, 2012

Description

Symptom

A vulnerability exists in the ITS-Services of the "Internal Service Request (ISR)" tool within the above components. A malicious user can exploit this flaw to:

  • Modify displayed application content without authorization.
  • Potentially obtain authentication information from other legitimate users.

This issue stems from insufficient encoding of OUTPUT parameters, leading to Cross-Site Scripting (XSS) vulnerabilities in the following ITS services: SPS1D, SPS2D, SR63D, SRGEN, SR00, SRPH, SR_LIBRARY, SR61, SR62, SRK1, SRK2, SRK3, SOR1, SH01, SH02, SR01, SR12, SR12_START, SR31, SR71_ERP, SR41, SR42.

Solution

To mitigate this vulnerability, apply SAP Note 1674219 or import the necessary changes via the relevant support package. Ensure that the corrections from SAP Notes 1621946 and 1488500 are also implemented, as they provide essential foundational fixes required for this correction to be effective.

WarningThis step must be executed manually and separately in each system after importing the note.

Reason and prerequisites

  • Steal authentication information, such as session data.
  • Impersonate users, potentially with administrative privileges, compromising application security.

References

Affected components

  • SAP_APPL 600
  • SAP_APPL 602
  • SAP_APPL 603
  • SAP_APPL 604
  • SAP_APPL 605
  • SAP_APPL 606

Full note on SAP: SAP Support Launchpad note 1674219

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More