Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

XSRF vulnerability External start of transactions with OKCode, SAP security note 1973081

SAP Note 1973081

SAP security note 1973081, "XSRF vulnerability: External start of transactions with OKCode". Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > ABAP Runtime Environment – ABAP Language Issues Only > Dynpro and CUA engine

Description

Symptom

An attacker can trick a victim user to execute an SAP GUI shortcut (SAP GUI for Windows), a Java start transaction (SAP GUI for Java) or to click the link (SAP GUI for HTML) and execute a state-changing action in the system with the credentials of the victim.

Solution

With this SAP Note we introduce switchable white lists to enable administrators to implement XSRF protection across the input channels. The white list mechanism is implemented in SAP backend and may replace input channel specific solutions.

White listing is available in NetWeaver 740 SP08 and for releases 700 to 731 by SAP Note 2055468, for documentation refer to SAP Note 1956086.

Further on, a learning mode assists administrators to maintain white lists, for details refer to SAP Notes 1919573 (implementation) and 1922712 (documentation).

Reason and prerequisites

The XSRF protection for BSP provided by SAP Notes 1458171 and 1520324, and ITS provided by SAP Note 1481392 shall be implemented. A generic solution is required and provided by this SAP Note in the solution area.

CVSS

Score 0

References

Affected components

  • BC-ABA-SC (valid from 05.01.2016)

Full note on SAP: SAP Support Launchpad note 1973081

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More