Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in WEBCUIF, SAP security note 1590555

SAP Note 1590555

SAP security note 1590555, “Unauthorized use of application functions in WEBCUIF”, is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can execute functions in WEBCUIF without authentication and authorization.

Solution

  • Refer to Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing Note 1590555.
  • Implement the correction instructions of Note 1590555:
    • Depending on your SAP release, implementing this note will create specific reports in your system to activate XSRF protection for the adapted BSP applications.
    • Execute these reports and specify a corresponding transport request number when prompted. This will enable the XSRF protection mechanisms necessary to secure WEBCUIF functions.

Implementing this note may also address issues referenced in Note 1736180 and Note 1738288.

Reason and prerequisites

WEBCUIF executes certain functions by referencing specific URLs. An attacker can trick an authenticated user’s browser into making a request with a specific URL and parameters, causing the function to execute with the user’s privileges. This can be achieved through cross-site scripting attacks or by presenting a malicious link to the victim.

References

Referenced by

  • Note 2522480 – WEBCUIF: Download of script file fails
  • Note 2522488 – WEBCUIF: Missing dependency causes syntax error

Full note on SAP: SAP Support Launchpad note 1590555

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More