Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in ICM, SAP security note 1467896

SAP Note 1467896
Medium priority

SAP security note 1467896, "Unauthorized use of application functions in ICM", released on 10.05.2011. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Client/Server Technology > Internet Communication Manager
PriorityCorrection with medium priority
StatusReleased for Customer
Released on10.05.2011

Description

Symptom

A malicious user can execute functions in the Internet Communication Manager (ICM) without proper authentication and authorization.

Solution

To mitigate this vulnerability, apply the necessary ICM patches as detailed in the “SP patch level” section of the SAP Security Note. Ensure that your ICM is updated to the specified patch levels or higher.

Reason and prerequisites

ICM executes certain functions by referencing specific URLs. A malicious user can trick an authenticated user’s browser into making a request containing a particular URL and specific parameters. This causes the function to execute with the privileges of the authenticated user. To successfully carry out this attack, the malicious user must meet special requirements, such as performing a cross-site scripting (XSS) attack or presenting a deceptive link to the victim.

CVSS

Score 0

Full note on SAP: SAP Support Launchpad note 1467896

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More