SAP security note 1430970, "Unauthorized Executing of Functions in Web Dynpro ABAP", is. Below are the symptom, SAP recommended solution and affected software components.
Description
Symptom
An attacker can execute functions of Web Dynpro ABAP applications without the relevant authentication and authorization. This can be achieved by exploiting cross-site scripting (XSS) vulnerabilities or by supplying the user with a specially crafted link, potentially allowing the attacker to perform actions with the user's privileges.
Solution
Implement the correction instructions provided in SAP Note 1430970 or import the relevant Support Package associated with your system version.
CVSS
Score 0
References
Affected components
- SAP_BASIS versions 700 to 702
- SAP_BASIS versions 710 to 720
Full note on SAP: SAP Support Launchpad note 1430970
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



