SAP security note 1511193, “XSRF protection for the CCMS Monitoring Console”, is a note released on September 22, 2016. Below are the symptom and the SAP recommended solution.
Description
Symptom
CCMS Monitoring Console is a stateful BSP application, which is vulnerable to Cross-Site Request Forgery (XSRF) attacks. An attacker can exploit this vulnerability by tricking an authenticated user’s browser into making unauthorized requests.
Solution
“XSRF Protection” has been activated for the CCMS Monitoring Console. Please import the relevant Support Package.
Reason and prerequisites
An attacker can execute certain functions by referencing specific URLs. By tricking an authenticated user’s browser into making a request with a crafted URL and specific parameters, the function is executed with the user’s privileges. Additionally, the attacker may use a Cross Site Scripting (XSS) attack to trigger the exploit or present a deceptive link for the victim to click.
References
Full note on SAP: SAP Support Launchpad note 1511193
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
