SAP Security Note
High priority
SAP security note 2114316, "Unauthorized use of application functions in SMP 3.0", is a program error note released on February 10, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can execute functions in SMP 3.0 without authentication and authorization.
Solution
Upgrade to SMP 3.0 SP05 PL01 to mitigate this vulnerability.
Reason and prerequisites
SMP 3.0 executes certain functions by referencing specific URLs. An attacker can trick an authenticated user’s browser into making a malicious request containing a specific URL and parameters, thereby executing functions with the user’s privileges. This can be achieved through cross-site scripting attacks or by presenting deceptive links to the victim.
CVSS
Score 6.8 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 2114316
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




