SAP Security Note
High priority
SAP security note 1612983, "Unauthorized use of appl. functions in mobile extension", is a program error note released on 11.10.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can execute functions in the mobile extension of mySAP without authentication and authorization.
Solution
Please use the correction instruction or the next service pack to solve the problem.
Reason and prerequisites
The mobile extension of mySAP executes certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. The malicious user may use a cross-site scripting attack to do this, or they may present a link to the victim.
CVSS
Score 0
References
This note refers to
Affected components
- SAP_BASIS 640
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 730
- SAP_BASIS 731
- SAP_BASIS 800 to 802
Full note on SAP: SAP Support Launchpad note 1612983
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
