SAP security note 1517963, "Unauthorized usage of functionality in workflow (ITS)", is released on December 14, 2010. Below are the symptom, reason and prerequisites, SAP recommended solution and references.
Description
Symptom
An attacker can trigger functionality in the Business Workflow area without the relevant authentication and authorization.
Solution
- Read Note 1481392 for additional information and further instructions. The corrections from Note 1481392 are a prerequisite for implementing this note.
- Implement the correction instructions contained in this note. The program ITS_XSRF_PARAM_BC_BMT_WFM (among other things) is created in your system.
- Execute the program ITS_XSRF_PARAM_BC_BMT_WFM and select the transport request when prompted. The program adds the service parameters for the adjusted ITS services.
Reason and prerequisites
Specified Internet services execute certain functions through referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the functions are executed in the Business Workflow area with the rights of the user. The attacker may use a Cross Site Scripting (XSS) attack or present a clickable link to the victim.
References
Full note on SAP: SAP Support Launchpad note 1517963
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



