Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in PA-PD-PM, SAP security note 1508981

SAP Note 1508981
High priority

SAP security note 1508981, "Unauthorized use of application functions in PA-PD-PM", is released on 08.11.2011. Below are the symptom and SAP recommended solution.

CategoryProgram error
PriorityCorrection with high priority
StatusReleased for Customer
Released on08.11.2011

Description

Symptom

An attacker can execute functions in 'PA-PD-PM' without authentication and authorization.

Solution

1. For additional information and instructions, see Note 1520324. The corrections from Note 1520324 are a prerequisite for implementing this note.

2. Implement the correction instructions provided in this note. Depending on your release, one of the following reports will be created in your system:

  • EA-HRGXX 110: BSP_XSRF_PARAM_HAP_DOC_110
  • EA-HRGXX 200: BSP_XSRF_PARAM_HAP_DOC_200
  • SAP_ABA 640: BSP_XSRF_PARAM_HAP_DOC_640
  • SAP_ABA 700: BSP_XSRF_PARAM_HAP_DOC_700
  • SAP_ABA 701: BSP_XSRF_PARAM_HAP_DOC_701
  • SAP_ABA 702: BSP_XSRF_PARAM_HAP_DOC_702
  • SAP_ABA 710: BSP_XSRF_PARAM_HAP_DOC_710
  • SAP_ABA 711: BSP_XSRF_PARAM_HAP_DOC_711
  • SAP_ABA 730: BSP_XSRF_PARAM_HAP_DOC_730

3. Execute the report and when requested, specify a relevant transport request number. The report will fill the database table BSPTEMPXSRFSTORE with relevant table entries for the BSP applications adapted by this note.

Reason and prerequisites

'PA-PD-PM' executes certain functions by referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. The attacker may use a cross-site scripting attack to do this, or they may present a link to the victim.

References

Full note on SAP: SAP Support Launchpad note 1508981

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More