Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in Config Uninstal, SAP security note 1631385

SAP Note 1631385

SAP security note 1631385, "Unauthorized use of application functions in Config Uninstal", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can execute functions in the KM Configuration Uninstaller Utility without authentication and authorization.

Solution

  • Deploy the patch containing the XSRF Protection Framework as detailed in SAP Note 1450166.
  • Apply the latest patch levels of the Security Correction Advisories (SCAs) as outlined in the Validity section of this note.

Reason and prerequisites

The Knowledge Management Configuration Uninstaller Utility executes certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the rights of the authenticated user. This can be achieved through a cross-site scripting attack or by presenting a deceptive link to the victim.

References

Affected components

  • Enterprise Portal > Enterprise Portal – Knowledge Management and Collaboration > Framework > Configuration Framework
  • PORTAL FRAMEWORK 7.02 (SP004 to SP030)
  • PORTAL PLATFORM 6.0_640 (SP025 to SP030)

Full note on SAP: SAP Support Launchpad note 1631385

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More