Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized usage of application functionality in IS-HER-CM, SAP security note 1511062

SAP Note 1511062

SAP security note 1511062, “Unauthorized usage of application functionality in IS-HER-CM”, is a note. Below are the symptom, reason and prerequisites, SAP recommended solution, references and the affected software components.

Description

Symptom

  • Ability to execute certain functions in IS-HER-CM without authentication.
  • Exploitation can occur through specific URLs and parameters.

Solution

  • Refer to SAP Note 1520324 for additional information and instructions. Implementing the corrections from this note is a prerequisite for applying this note.
  • Implement the correction instructions provided in this note. This will create the report BSP_XSRF_PARAM_PMIQ_<release> in your system.
  • Execute the report BSP_XSRF_PARAM_PMIQ_<release> and provide a corresponding transport request number when prompted. This will populate the BSPTEMPXSRFSTORE database table with the necessary entries for the BSP applications modified by this note.

Reason and prerequisites

IS-HER-CM performs specific functions by referencing certain URLs. An attacker can trick an authenticated user’s browser into making a request with these URLs and parameters, causing the function to execute with the user’s privileges. This can be achieved via:

  • Cross Site Scripting (XSS) attacks.
  • Presenting malicious links to the victim.

References

Affected components

  • IS-PS-CA (472, 600, 602, 603, 604, 605)

Full note on SAP: SAP Support Launchpad note 1511062

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More