SAP security note 1590555, “Unauthorized use of application functions in WEBCUIF”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can execute functions in WEBCUIF without authentication and authorization.
Solution
- Refer to Note 1520324 for additional information and instructions. The corrections from this note are a prerequisite for implementing Note 1590555.
- Implement the correction instructions of Note 1590555:
- Depending on your SAP release, implementing this note will create specific reports in your system to activate XSRF protection for the adapted BSP applications.
- Execute these reports and specify a corresponding transport request number when prompted. This will enable the XSRF protection mechanisms necessary to secure WEBCUIF functions.
Implementing this note may also address issues referenced in Note 1736180 and Note 1738288.
Reason and prerequisites
WEBCUIF executes certain functions by referencing specific URLs. An attacker can trick an authenticated user’s browser into making a request with a specific URL and parameters, causing the function to execute with the user’s privileges. This can be achieved through cross-site scripting attacks or by presenting a malicious link to the victim.
References
Referenced by
- Note 2522480 – WEBCUIF: Download of script file fails
- Note 2522488 – WEBCUIF: Missing dependency causes syntax error
Full note on SAP: SAP Support Launchpad note 1590555
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



