SAP security note 1488038, "Unauthorized usage of test tool of system login". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in the system login test tool for URL fields without authentication and authorization.
Solution
Please import the ABAP correction in the relevant Basis support package.
Reason and prerequisites
The test tool of system login executes certain functions by referencing specific URLs. When an attacker tricks an authenticated user's browser into making a request containing a particular URL and specific parameters, the function is executed with the user's rights. Additionally, if present, the attacker may exploit a Cross Site Scripting (XSS) vulnerability.
References
Affected components
- SAP_BASIS 640
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 730
Full note on SAP: SAP Support Launchpad note 1488038
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



