Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in WDA, SAP security note 1586741

SAP Note 1586741
SAP Security Note
High priority

SAP security note 1586741, "Unauthorized use of application functions in WDA", is a program error note released on July 12, 2011. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Web Dynpro > Web Dynpro ABAP (BC-WD-ABA)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onJuly 12, 2011

Description

Symptom

A malicious user can execute functions in Web Dynpro ABAP without authentication and authorization.

Solution

In the affected application in Web Dynpro ABAP, only test BSP applications are involved. These test BSP applications are deleted with this correction. Implement the correction instructions or import the relevant Support Package.

Reason and prerequisites

Web Dynpro ABAP executes certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. The malicious user may use a cross-site scripting attack to achieve this or present a deceptive link to the victim.

Full note on SAP: SAP Support Launchpad note 1586741

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More