Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in FIN-CGV-MIC, SAP security note 1511316

SAP Note 1511316
High priority

SAP security note 1511316, “Unauthorized use of application functions in FIN-CGV-MIC”, released on 12.04.2011. Below are the symptom and SAP recommended solution.

ComponentFIN-CGV-MIC (Financials > Corporate Governance > Management of internal controls)
PriorityCorrection with high priority
Released on12.04.2011

Description

Symptom

A malicious user can execute functions in FIN-CGV-MIC without authentication and authorization.

Solution

Apply the following correction instructions and perform the necessary manual activities.

Reason and prerequisites

FIN-CGV-MIC executes certain functions by referencing specific URLs. A malicious user can trick an authenticated user’s browser into making a request with a specific URL and parameters, causing the function to execute with the user’s rights. This can be achieved through cross-site scripting attacks or by presenting a deceptive link to the victim.

References

Full note on SAP: SAP Support Launchpad note 1511316

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More