Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in SAP_HR, SAP security note 1509016

SAP Note 1509016

SAP security note 1509016, "Unauthorized usage of application functionality in SAP_HR". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can trigger functionality in SAP_HR without authentication and authorization.

Solution

The correction will be delivered with a Support Package. The relationship between the Support Package and the technical name given under "Support Packages" is described in SAP note 1232082.

Alternatively, you can implement the correction instructions:

  • Refer to note 1481392 for additional information and instructions. The corrections from note 1481392 are a prerequisite for implementation of this note.
  • Implement the correction instructions of this note. This will also create the report RH_XSRF_PARAM_SAP_HR_ITS in your system.
  • Execute the report and specify a corresponding transport request number when prompted. The report will add service parameters for the adapted ITS services (maintained via the GUI configuration pushbutton for a service within transaction SICF).

Reason and prerequisites

SAP_HR executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user.

If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.

References

Affected components

  • SAP_HRGXX 500
  • SAP_HRGXX 600
  • SAP_HRGXX 604

Full note on SAP: SAP Support Launchpad note 1509016

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More