SAP security note 1525664, “Unauthorized usage of appl. functionality in Plant Manager”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in Plant Manager 1.0 without authentication and authorization.
Note the following:
- Plant Manager 1.0 is marked as obsolete as of Release ERP 2005 and has been replaced by Plant Manager 2.0.
- Plant Manager 2.0 uses different technology and is therefore not affected.
Solution
- Implement Note 1520324.
- Apply the correction instructions contained in this note. This will create the report BSP_XSRF_PARAM_PLANT_MANAGER1 in your system.
- Execute the report and specify a transport request. The report creates entries in the table BSPTEMPXSRFSTORE; these entries must be transported.
Reason and prerequisites
The BSP application executes certain functions by referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the user’s rights. If present, the attacker may use a Cross Site Scripting (XSS) attack to trigger the exploit or use an approach in which a link is presented for the victim to click.
References
Affected components
- SAP_APPL versions 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1525664
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



