Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of ITS in SRM-EBP-ADM-USR, SAP security note 1670438

SAP Note 1670438
SAP Security Note
High priority

SAP security note 1670438, “Unauthorized modification of ITS in SRM-EBP-ADM-USR”, is a program error note released on May 8, 2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSupplier Relationship Management > SRM > Organization/Business Partner Administration > User Administration
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onMay 8, 2012
LanguageEnglish

Description

Symptom

A vulnerability exists in SRM-EBP-ADM-USR that allows a malicious user to modify displayed application content without authorization. This can be exploited to obtain authentication information from other legitimate users.

Solution

Apply this SAP Security Note or import the changes via the relevant support package.

Reason and prerequisites

The ITS Services BBPAT03, BBPUM01, BBPUM02, and BBPVENDOR within SRM-EBP-ADM-USR do not sufficiently encode OUTPUT parameters, resulting in a cross-site scripting issue. This vulnerability can be used to steal another user’s authentication information, potentially allowing impersonation and access to sensitive data with the same rights as the target user. If an administrator is impersonated, the security of the application may be fully compromised.

Affected components

  • SRM_SERVER 500
  • SRM_SERVER 550
  • SRM_SERVER 600
  • SRM_SERVER 700
  • SRM_SERVER 701
  • SRM_SERVER 702

Full note on SAP: SAP Support Launchpad note 1670438

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More