SAP Security Note
High priority
SAP security note 1589377, "Unauthorized use of applic. functions in In-Store MIM Mobile", released on 09.08.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can execute functions in Mobile Inventory Management and Physical Inventory with ITSmobile (In-Store MIM Mobile) without authentication and authorization.
Issue: Cross-site request forgery (XSRF) allows malicious users to execute functions with the rights of an authenticated user by tricking their browser into making unauthorized requests.
Affected functions: Mobile Inventory Management and Physical Inventory in ITSmobile.
Solution
- Prerequisite: apply the corrections from SAP Note 1481392 for Cross Site Request Forgery Protection for ITS.
- Implement corrections: follow the instructions in this note to create and execute the report ITS_XSRF_PARAM_MIM_MOBILE in your system. This will add necessary service parameters for the ITS service.
References
Full note on SAP: SAP Support Launchpad note 1589377
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
