Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in BPC 7.5, SAP security note 1962860

SAP Note 1962860

SAP security note 1962860, “Unauthorized Use of Application Functions in BPC 7.5”, is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can execute functions in BPC 7.5 without authentication and authorization.

Solution

Corrections have been made to the BPC Client and .NET Server applications and are available in:

  • BPC 7.5 SP17
  • BPC 7.53 SP08
  • BPC 7.54 SP03

Corrections have also been made to ODBO SP11 to be compatible with these BPC .NET Server versions.

Reason and prerequisites

BPC Client applications (Excel client, Admin client, Server Manager, etc.) execute certain functions by referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. The attacker may use a cross-site scripting attack to do this, or they may present a link to the victim.

CVSS

Score 6.8 Vector: AV:N/AC:M/AU:N/C:P/I:P/A:P

References

Affected components

  • SAPCPMBPCCLNT: 750 to 750
  • CPM_BPC_ODBO: 100 to 100
  • CPM_BPC_NW: 750 to 750

Full note on SAP: SAP Support Launchpad note 1962860

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More