SAP security note 1511594, “Unauthorized usage of application Customer Bill of Services”, is a note. Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in the Bill of Services without proper authentication and authorization. Specifically, the user can create new service entry sheets without the necessary permissions.
- Unauthorized creation of service entry sheets in the Bill of Services application.
Solution
- Prerequisite: Refer to SAP Note 1481392 for additional information and instructions. Implementing the corrections from this note is mandatory before proceeding.
- Implement corrections: Follow the correction instructions outlined in this note. This will create the report
RITS_XSRF_PARAM_BOS02in your system. - Execute report: Run the report
RITS_XSRF_PARAM_BOS02and provide a corresponding transport request number when prompted. This report will add service parameters for the adapted ITS services, which can be maintained via the GUI configuration pushbutton for a service within transaction SICF.
Reason and prerequisites
BOS executes certain functions by referencing specific URLs. An attacker can trick an authenticated user's browser into making a request with a malicious URL and specific parameters. This causes the function to execute with the user's rights. Attackers may use Cross Site Scripting (XSS) to trigger the exploit or present a malicious link to the victim.
Affected components
- ECC-DIMP (500, 600, 602, 603, 604, 605)
Full note on SAP: SAP Support Launchpad note 1511594
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



