Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality, SAP security note 1514098

SAP Note 1514098
SAP Security Note
High priority

SAP security note 1514098, "Unauthorized Usage of Application Functionality", is a program error note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCRM-MKT (Customer Relationship Management > Marketing)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

A malicious user can trigger functionality in the following BSP applications without authentication and authorization: CARPTEST, CRM_MKTTG_SEGAP, CRM_MKTCA_UI, CRM_MKTIMEX_MON.

Solution

  • Refer to Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing this note.
  • Implement the correction instructions of this note. This will create the report BSP_XSRF_PARAM_CRM_MKT in your system.
  • Execute the report BSP_XSRF_PARAM_CRM_MKT and specify a corresponding transport request number when prompted. The report will populate the database table BSPTEMPXSRFSTORE with entries for the BSP applications adapted by this note.

Reason and prerequisites

The mentioned BSP applications execute certain functions by referencing specific URLs. An attacker can trick an authenticated user’s browser into making a request containing certain URLs and parameters, causing functions to execute with the user’s rights.

If present, the attacker may use a Cross Site Scripting attack to trigger the exploit or present a clickable link to the victim.

CVSS

Score 0

References

Affected components

  • BBPCRM 400
  • BBPCRM 500
  • BBPCRM 520
  • BBPCRM 600
  • BBPCRM 700
  • BBPCRM 701

Full note on SAP: SAP Support Launchpad note 1514098

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More