SAP security note 1631385, "Unauthorized use of application functions in Config Uninstal", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can execute functions in the KM Configuration Uninstaller Utility without authentication and authorization.
Solution
- Deploy the patch containing the XSRF Protection Framework as detailed in SAP Note 1450166.
- Apply the latest patch levels of the Security Correction Advisories (SCAs) as outlined in the Validity section of this note.
Reason and prerequisites
The Knowledge Management Configuration Uninstaller Utility executes certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the rights of the authenticated user. This can be achieved through a cross-site scripting attack or by presenting a deceptive link to the victim.
References
This note refers to
Affected components
- Enterprise Portal > Enterprise Portal – Knowledge Management and Collaboration > Framework > Configuration Framework
- PORTAL FRAMEWORK 7.02 (SP004 to SP030)
- PORTAL PLATFORM 6.0_640 (SP025 to SP030)
Full note on SAP: SAP Support Launchpad note 1631385
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
