Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of functionality in workflow (ITS), SAP security note 1517963

SAP Note 1517963High priority

SAP security note 1517963, "Unauthorized usage of functionality in workflow (ITS)", is released on December 14, 2010. Below are the symptom, reason and prerequisites, SAP recommended solution and references.

ComponentBasis Components > Business Management > Business Workflow > Web Integration
PriorityCorrection with high priority
StatusReleased for Customer
Released onDecember 14, 2010
LanguageEnglish

Description

Symptom

An attacker can trigger functionality in the Business Workflow area without the relevant authentication and authorization.

Solution

  • Read Note 1481392 for additional information and further instructions. The corrections from Note 1481392 are a prerequisite for implementing this note.
  • Implement the correction instructions contained in this note. The program ITS_XSRF_PARAM_BC_BMT_WFM (among other things) is created in your system.
  • Execute the program ITS_XSRF_PARAM_BC_BMT_WFM and select the transport request when prompted. The program adds the service parameters for the adjusted ITS services.

Reason and prerequisites

Specified Internet services execute certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the functions are executed in the Business Workflow area with the rights of the user. The attacker may use a Cross Site Scripting (XSS) attack or present a clickable link to the victim.

References

Full note on SAP: SAP Support Launchpad note 1517963

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More