Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of appl. functionality in DocBuilder, SAP security note 1507377

SAP Note 1507377
SAP Security Note
High priority

SAP security note 1507377, "Unauthorized usage of application functionality in DocBuilder", is a program error note released on 09.11.2010. Below are the symptom and SAP recommended solution.

ComponentCross-Application Components > General Application Functions > Document Builder (CA-GTF-DOB)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on09.11.2010
LanguageEnglish

Description

Symptom

A malicious user can trigger functionality in DocumentBuilder without authentication and authorization.

Solution

Apply the Support Package and/or the attached correction.

Reason and prerequisites

DocumentBuilder executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user. If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.

Full note on SAP: SAP Support Launchpad note 1507377

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More