SAP Security Note
High priority
SAP security note 1506350, “Unauthorized usage of application functionality in FI-AA”, is a program error note released on 14.12.2010. Below are the symptom, reason and prerequisites, and the SAP recommended solution.
Description
Symptom
A malicious user can execute functions without having sufficient authentication and authorization.
Solution
- See Note 1481392 for additional information and instructions. The correction instructions contained in Note 1481392 must be implemented before you implement this note.
- Implement the correction instructions and create the report ITS_XSRF_PARAM_FIAA_ALL in your system.
- Execute the report ITS_XSRF_PARAM_FIAA_ALL and enter a relevant transport request when prompted. The report inserts some service parameters for the adjusted ITS services (these are usually entered by choosing the button for the GUI settings in transaction SICF for maintaining ITS services).
Reason and prerequisites
FI-AA executes certain internet services through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user.
Full note on SAP: SAP Support Launchpad note 1506350
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
