Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

XSRF protection for the CCMS Monitoring Console, SAP security note 1511193

SAP Note 1511193

SAP security note 1511193, “XSRF protection for the CCMS Monitoring Console”, is a note released on September 22, 2016. Below are the symptom and the SAP recommended solution.

ComponentBasis Components > Computer Center Management System (CCMS) > CCMS Monitoring & Alerting (BC-CCM-MON)
Released onSeptember 22, 2016

Description

Symptom

CCMS Monitoring Console is a stateful BSP application, which is vulnerable to Cross-Site Request Forgery (XSRF) attacks. An attacker can exploit this vulnerability by tricking an authenticated user’s browser into making unauthorized requests.

Solution

“XSRF Protection” has been activated for the CCMS Monitoring Console. Please import the relevant Support Package.

Reason and prerequisites

An attacker can execute certain functions by referencing specific URLs. By tricking an authenticated user’s browser into making a request with a crafted URL and specific parameters, the function is executed with the user’s privileges. Additionally, the attacker may use a Cross Site Scripting (XSS) attack to trigger the exploit or present a deceptive link for the victim to click.

References

Full note on SAP: SAP Support Launchpad note 1511193

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More