SAP security note 1514483, "Unauthorized usage of application functionality in EA-HR", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in EA-HR without authentication and authorization.
Solution
- Refer to Note 1481392 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.
- Implement the correction instructions of this note. This will also create the report RH_XSRF_PARAM_EA_HR_ITS (or RH_XSRF_PARAM_EAHR_ITS in Release 500) in your system.
- Execute the report in the development system and specify a corresponding transport request number when prompted. The report will add service parameters for the adapted ITS services (maintained via the GUI configuration pushbutton for a service within transaction SICF).
Reason and prerequisites
EA-HR executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user.
If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.
CVSS
Score 0
References
Affected components
- PA-AS (Personnel Management > HR Processes & Forms)
- EA-HRGXX versions 500, 600, 602, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1514483
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
