Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in PPM-PRO, SAP security note 1523140

SAP Note 1523140

SAP security note 1523140, "Unauthorized usage of application functionality in PPM-PRO", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can trigger functionality in PPM-PRO/cProjects without proper authentication and authorization. This results in unauthorized access to functionalities in PPM-PRO/cProjects and potential execution of functions with the rights of an authenticated user.

Solution

Implement the correction instructions provided in this note. This will also create the report BSP_XSRF_PARAM_CPROJECTS in your system. Note 1520324 must be implemented prior to this note.

Reason and prerequisites

PPM-PRO executes functions through specific URLs. An attacker can trick an authenticated user’s browser into making a malicious request containing specific URLs and parameters, leading to unauthorized actions.

References

Affected components

  • PPM-PRO 300
  • PPM-PRO 310_620 to 310_640
  • PPM-PRO 400

Full note on SAP: SAP Support Launchpad note 1523140

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.