High priority
SAP security note 1511316, “Unauthorized use of application functions in FIN-CGV-MIC”, released on 12.04.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can execute functions in FIN-CGV-MIC without authentication and authorization.
Solution
Apply the following correction instructions and perform the necessary manual activities.
Reason and prerequisites
FIN-CGV-MIC executes certain functions by referencing specific URLs. A malicious user can trick an authenticated user’s browser into making a request with a specific URL and parameters, causing the function to execute with the user’s rights. This can be achieved through cross-site scripting attacks or by presenting a deceptive link to the victim.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1511316
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
