SAP security note 1623106, "Unauthorized use of application functionality in BC-SRV-ARL". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in BC-SRV-ARL without proper authentication and authorization.
- An attacker tricks an authenticated user’s browser into making a request containing a specific URL and parameters.
- The function executes with the user’s rights.
- Possible exploitation methods include Cross Site Scripting (XSS) or presenting a clickable link to the victim.
Solution
For the stateless BSP application:
- Refer to Notes 1520324 and 1551982: These notes provide additional information and instructions. Corrections from these notes are prerequisites for implementing this note.
- Implement Correction Instructions: Follow the correction instructions outlined in this note. This will create the report
BSP_XSRF_PARAM_BC_SRV_ARLin your system. - Execute the Report: Run the report
BSP_XSRF_PARAM_BC_SRV_ARL. When prompted, specify a corresponding transport request number. This action will activate XSRF protection for the BSP applications modified by this note.
Reason and prerequisites
When an attacker deceives an authenticated user into executing a crafted request, the application may perform unauthorized actions with the user’s privileges.
Affected components
- SAP_BASIS (620 to 640)
Full note on SAP: SAP Support Launchpad note 1623106
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



