Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application Customer Bill of Services., SAP security note 1511594

SAP Note 1511594

SAP security note 1511594, “Unauthorized usage of application Customer Bill of Services”, is a note. Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can trigger functionality in the Bill of Services without proper authentication and authorization. Specifically, the user can create new service entry sheets without the necessary permissions.

  • Unauthorized creation of service entry sheets in the Bill of Services application.

Solution

  • Prerequisite: Refer to SAP Note 1481392 for additional information and instructions. Implementing the corrections from this note is mandatory before proceeding.
  • Implement corrections: Follow the correction instructions outlined in this note. This will create the report RITS_XSRF_PARAM_BOS02 in your system.
  • Execute report: Run the report RITS_XSRF_PARAM_BOS02 and provide a corresponding transport request number when prompted. This report will add service parameters for the adapted ITS services, which can be maintained via the GUI configuration pushbutton for a service within transaction SICF.

Reason and prerequisites

BOS executes certain functions by referencing specific URLs. An attacker can trick an authenticated user's browser into making a request with a malicious URL and specific parameters. This causes the function to execute with the user's rights. Attackers may use Cross Site Scripting (XSS) to trigger the exploit or present a malicious link to the victim.

Affected components

  • ECC-DIMP (500, 600, 602, 603, 604, 605)

Full note on SAP: SAP Support Launchpad note 1511594

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More