Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of appl. functionality in Plant Manager, SAP security note 1525664

SAP Note 1525664

SAP security note 1525664, “Unauthorized usage of appl. functionality in Plant Manager”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can trigger functionality in Plant Manager 1.0 without authentication and authorization.

Note the following:

  • Plant Manager 1.0 is marked as obsolete as of Release ERP 2005 and has been replaced by Plant Manager 2.0.
  • Plant Manager 2.0 uses different technology and is therefore not affected.

Solution

  • Implement Note 1520324.
  • Apply the correction instructions contained in this note. This will create the report BSP_XSRF_PARAM_PLANT_MANAGER1 in your system.
  • Execute the report and specify a transport request. The report creates entries in the table BSPTEMPXSRFSTORE; these entries must be transported.

Reason and prerequisites

The BSP application executes certain functions by referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the user’s rights. If present, the attacker may use a Cross Site Scripting (XSS) attack to trigger the exploit or use an approach in which a link is presented for the victim to click.

References

Affected components

  • SAP_APPL versions 500, 600, 602, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1525664

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More