SAP Security Note
High priority
SAP security note 1624872, "Unauthorized use of application functions in Prod Designer UI", is released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can execute functions in the Product Designer UI without proper authentication and authorization.
Solution
- For additional information and instructions, refer to Note 1520324. The corrections from this note must be implemented before applying this security note.
- Follow the correction instructions provided in this note to address the vulnerability.
- Run the report BSP_XSRF_PARAM_PLM_PPM_PDN and provide a relevant transport request number when prompted. This report will populate the BSPTEMPXSRFSTORE database table with necessary entries for the BSP applications modified by this note.
Reason and prerequisites
The Product Designer UI executes certain functions by referencing specific URLs. A malicious user can trick an authenticated user’s browser into making a request with specific URLs and parameters, allowing the function to execute with the authenticated user’s privileges. This can be achieved through cross-site scripting attacks or by presenting a deceptive link to the victim.
Affected components
- EA-APPL 110
- EA-APPL 200
- EA-APPL 500
- EA-APPL 600
- EA-APPL 602
- EA-APPL 603
- EA-APPL 604
- EA-APPL 605
Full note on SAP: SAP Support Launchpad note 1624872
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
