SAP Security Note
High priority
SAP security note 1513975, "Unauthorized usage of appl. functionality in Web Request", is a note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in CRM Web Request applications without authentication and authorization.
Solution
- Refer to Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.
- Implement the correction instructions of this note. This will also create the report CRM_BSP_XSRF_PARAM_WEBREQ1 in your system.
- Execute the report CRM_BSP_XSRF_PARAM_WEBREQ1 and specify a corresponding transport request number when prompted. The report will fill the database table BSPTEMPXSRFSTORE with corresponding table entries for the BSP applications adapted by this note.
Reason and prerequisites
The BSP applications CRM_WR_SHOW_SIG, WFF_START, and CRM_BSP_WEBREQF execute certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the user’s rights.
If present, the attacker may use a Cross Site Scripting attack to trigger the exploit or present a clickable link to the victim.
CVSS
Score 0
References
This note refers to
Referenced by
Affected components
- BBPCRM 400
- BBPCRM 500
- BBPCRM 520
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
Full note on SAP: SAP Support Launchpad note 1513975
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
