Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized executing of functions in Web Dynpro ABAP, SAP security note 1430970

SAP Note 1430970

SAP security note 1430970, "Unauthorized Executing of Functions in Web Dynpro ABAP", is. Below are the symptom, SAP recommended solution and affected software components.

Description

Symptom

An attacker can execute functions of Web Dynpro ABAP applications without the relevant authentication and authorization. This can be achieved by exploiting cross-site scripting (XSS) vulnerabilities or by supplying the user with a specially crafted link, potentially allowing the attacker to perform actions with the user's privileges.

Solution

Implement the correction instructions provided in SAP Note 1430970 or import the relevant Support Package associated with your system version.

CVSS

Score 0

References

Affected components

  • SAP_BASIS versions 700 to 702
  • SAP_BASIS versions 710 to 720

Full note on SAP: SAP Support Launchpad note 1430970

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More