Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functionality in BC-SRV-ARL, SAP security note 1623106

SAP Note 1623106

SAP security note 1623106, "Unauthorized use of application functionality in BC-SRV-ARL". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can trigger functionality in BC-SRV-ARL without proper authentication and authorization.

  • An attacker tricks an authenticated user’s browser into making a request containing a specific URL and parameters.
  • The function executes with the user’s rights.
  • Possible exploitation methods include Cross Site Scripting (XSS) or presenting a clickable link to the victim.

Solution

For the stateless BSP application:

  1. Refer to Notes 1520324 and 1551982: These notes provide additional information and instructions. Corrections from these notes are prerequisites for implementing this note.
  2. Implement Correction Instructions: Follow the correction instructions outlined in this note. This will create the report BSP_XSRF_PARAM_BC_SRV_ARL in your system.
  3. Execute the Report: Run the report BSP_XSRF_PARAM_BC_SRV_ARL. When prompted, specify a corresponding transport request number. This action will activate XSRF protection for the BSP applications modified by this note.

Reason and prerequisites

When an attacker deceives an authenticated user into executing a crafted request, the application may perform unauthorized actions with the user’s privileges.

Affected components

  • SAP_BASIS (620 to 640)

Full note on SAP: SAP Support Launchpad note 1623106

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More