Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in CRM planning, SAP security note 1554676

SAP Note 1554676

SAP security note 1554676, “Unauthorized use of application functions in CRM planning”, is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

A malicious user can execute functions in CRM planning without authentication and authorization.

Solution

SAP NetWeaver BW 7.00

SAP NetWeaver BW 7.01 (SAP NW BW7.0 EnhP 1)

SAP NetWeaver BW 7.02 (SAP NW BW7.0 EnhP 2)

SAP NetWeaver BW 7.11

SAP NetWeaver BW 7.30

Reason and prerequisites

The CRM-MKT-MPL component in BW-PLA-BPS executes certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. This can be achieved through a cross-site scripting (XSS) attack or by presenting a deceptive link to the victim.

Full note on SAP: SAP Support Launchpad note 1554676

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More