SAP security note 1509638, "Unauthorized usage of application functionality in SSR", is released on 14.12.2010. Below is the SAP recommended solution.
Description
Solution
- Refer to SAP Note 1481392: Additional Information and Instructions Note 1481392 must be implemented as a prerequisite before applying this note.
- Implement Correction Instructions: Download for SNOTE Following the correction instructions will create the report
ITS_XSRF_PARAM_IS_OIL_SSRin your system. - Execute the Report: Run
ITS_XSRF_PARAM_IS_OIL_SSRand specify a corresponding transport request number when prompted. This report will add the necessary service parameters for the adapted ITS services, which can be managed via the GUI configuration in transaction SICF.
Reason and prerequisites
The SAP IS-Oil Store Workbench executes certain functions by referencing specific URLs. An attacker can trick an authenticated user's browser into making a request containing a particular URL and specific parameters, causing the function to execute with the user's permissions. Potential attack vectors include Cross-Site Scripting (XSS) or presenting a deceptive link for the victim to click.
Full note on SAP: SAP Support Launchpad note 1509638
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
