Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in SMP 3.0, SAP security note 2114316

SAP Note 2114316
SAP Security Note
High priority

SAP security note 2114316, "Unauthorized use of application functions in SMP 3.0", is a program error note released on February 10, 2015. Below are the symptom and SAP recommended solution.

CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Released onFebruary 10, 2015

Description

Symptom

An attacker can execute functions in SMP 3.0 without authentication and authorization.

Solution

Upgrade to SMP 3.0 SP05 PL01 to mitigate this vulnerability.

Reason and prerequisites

SMP 3.0 executes certain functions by referencing specific URLs. An attacker can trick an authenticated user’s browser into making a malicious request containing a specific URL and parameters, thereby executing functions with the user’s privileges. This can be achieved through cross-site scripting attacks or by presenting deceptive links to the victim.

CVSS

Score 6.8 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Full note on SAP: SAP Support Launchpad note 2114316

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More