Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of appl. functions in mobile extension, SAP security note 1612983

SAP Note 1612983
SAP Security Note
High priority

SAP security note 1612983, "Unauthorized use of appl. functions in mobile extension", is a program error note released on 11.10.2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Web Dynpro > Web Dynpro ABAP
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on11.10.2011
LanguageEnglish

Description

Symptom

A malicious user can execute functions in the mobile extension of mySAP without authentication and authorization.

Solution

Please use the correction instruction or the next service pack to solve the problem.

Reason and prerequisites

The mobile extension of mySAP executes certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. The malicious user may use a cross-site scripting attack to do this, or they may present a link to the victim.

CVSS

Score 0

References

Affected components

  • SAP_BASIS 640
  • SAP_BASIS 700 to 702
  • SAP_BASIS 710 to 730
  • SAP_BASIS 731
  • SAP_BASIS 800 to 802

Full note on SAP: SAP Support Launchpad note 1612983

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More