SAP security note 1557613, "Update #1 to Security Note 1508281". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Additional workarounds are provided for the vulnerability. Unauthorized usage of application functionality in BC-SRV-RM addressed in Security Note 1508281.
Solution
Please implement the note.
Reason and prerequisites
In lower Support Package levels of some releases, the built-in XSRF flag and Start up page flags are not available. For example, in 700 release SP 21, the flags to set XSRF and start up page are not available.
References
- SAP Note 1532403 – BSP XSRF framework as transport files
- SAP Note 1508281 – Unauthorized usage of application functionality in BC-SRV-RM
Affected components
- SAP_BASIS: 640 to 640
- SAP_BASIS: 700 to 702
- SAP_BASIS: 710 to 730
Full note on SAP: SAP Support Launchpad note 1557613
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
