SAP security note 1565397, "Unauthorized modification of content in BSP DSWP_URL_LAUNCH", released on May 10, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The BSP application DSWP_URL_LAUNCH can be exploited by malicious users to modify displayed application content without authorization. Additionally, attackers may obtain authentication information from legitimate users, potentially leading to unauthorized access and impersonation.
Solution
- Deactivate the vulnerable service: If the BSP application DSWP_URL_LAUNCH is active in your system, deactivate it using transaction SICF. This service is not required for standard operations.
- Implement corrections: Apply the provided correction instructions to ensure that the service remains deactivated, even if accidentally reactivated.
References
- SAP Note 1552585 – SAP Solution Manager: Basic functions 7.1 SP1
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- ST 400
- ST 710
Full note on SAP: SAP Support Launchpad note 1565397
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




