Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in PA-ER, SAP security note 1509014

SAP Note 1509014

SAP security note 1509014, "Unauthorized usage of application functionality in PA-ER". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can trigger functionality in PA-ER without authentication and authorization.

Solution

The correction will be delivered with a Support Package. Alternatively, you can implement the correction instructions:

  • Refer to note 1520324 for additional information and instructions. The corrections from note 1520324 are a prerequisite for implementation of this note.
  • Implement the correction instructions of this note. This will also create the report RCF_BSP_XSRF_PARAM_TRANSPORT in your system.
  • Execute the report in your development system and specify a corresponding transport request number when prompted. The report will fill the database table BSPTEMPXSRFSTORE with corresponding table entries for the BSP applications adapted by this note.

Reason and prerequisites

PA-ER executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user.

If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.

Side effects

References

Full note on SAP: SAP Support Launchpad note 1509014

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More