SAP security note 1519704, "Unauthorized usage of application functionality in CNW1/CNW4". Below are the symptom and SAP recommended solution.
Description
Symptom
A critical vulnerability has been identified in the CNW1 and CNW4 services of the SAP Project System (PS) component. This issue allows malicious users to execute certain functionalities without proper authentication and authorization, potentially leading to unauthorized actions within the system.
An attacker can exploit this vulnerability by tricking an authenticated user’s browser into making a request with specific URLs and parameters. This results in the execution of functions with the user’s privileges. Additionally, if present, an attacker may leverage Cross Site Scripting (XSS) to facilitate the exploit or use deceptive links to trick victims into executing the malicious requests.
Solution
For customers using the EHP5 release, follow these manual steps to mitigate the vulnerability:
- Access transaction
SICFin the SAP GUI. - For each service (CNW1 and CNW4): enter the service name in SICF (typically found under
/sap/bc/gui/sap/its/<service>), execute the service to display its settings, double-click on the service name in the service tree to switch to change mode, select the GUI Configuration, add the parameter~XSRFCHECKwith the value1, and save the changes. - Refer to SAP Note 1481392 for comprehensive information and further instructions. Implementing corrections from this note is a prerequisite for applying the current note. Execute the report
ITS_XSRF_PARAM_PScreated by this note. When prompted, provide the appropriate transport request number. This report will add necessary service parameters for the adapted ITS services.
References
- SAP Note 1481392 – Cross Site Request Forgery Protection for ITS
Full note on SAP: SAP Support Launchpad note 1519704
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
