Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in BC-SRV-RM, SAP security note 1508281

SAP Note 1508281
SAP Security Note
Medium priority

SAP security note 1508281, "Unauthorized usage of application functionality in BC-SRV-RM", is a note released on 12.04.2011. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Basis Services/Communication Interfaces > SAP Records Management
PriorityCorrection with medium priority
TypeSAP Security Note
Version11
StatusReleased for Customer
Released on12.04.2011

Description

Symptom

A malicious user can trigger functionality in BC-SRV-RM without authentication and authorization.

This security note has been updated. For more detailed information, see Security Note 1557613.

Solution

Implement the correction instructions or import the relevant Support Package.

Reason and prerequisites

BC-SRV-RM executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user.

If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.

References

Full note on SAP: SAP Support Launchpad note 1508281

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More