Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in CNW1/CNW4, SAP security note 1519704

SAP Note 1519704

SAP security note 1519704, "Unauthorized usage of application functionality in CNW1/CNW4". Below are the symptom and SAP recommended solution.

Description

Symptom

A critical vulnerability has been identified in the CNW1 and CNW4 services of the SAP Project System (PS) component. This issue allows malicious users to execute certain functionalities without proper authentication and authorization, potentially leading to unauthorized actions within the system.

An attacker can exploit this vulnerability by tricking an authenticated user’s browser into making a request with specific URLs and parameters. This results in the execution of functions with the user’s privileges. Additionally, if present, an attacker may leverage Cross Site Scripting (XSS) to facilitate the exploit or use deceptive links to trick victims into executing the malicious requests.

Solution

For customers using the EHP5 release, follow these manual steps to mitigate the vulnerability:

  • Access transaction SICF in the SAP GUI.
  • For each service (CNW1 and CNW4): enter the service name in SICF (typically found under /sap/bc/gui/sap/its/<service>), execute the service to display its settings, double-click on the service name in the service tree to switch to change mode, select the GUI Configuration, add the parameter ~XSRFCHECK with the value 1, and save the changes.
  • Refer to SAP Note 1481392 for comprehensive information and further instructions. Implementing corrections from this note is a prerequisite for applying the current note. Execute the report ITS_XSRF_PARAM_PS created by this note. When prompted, provide the appropriate transport request number. This report will add necessary service parameters for the adapted ITS services.

References

Full note on SAP: SAP Support Launchpad note 1519704

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More