SAP security note 1728500, “Unauthorized use of SOAP-Processor 620”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP has released Security Note 1728500 addressing a critical vulnerability in the SOAP Processor 620 (ICF Service for /sap/bc/soap/rfc). This vulnerability allows attackers to execute functions without proper authentication and authorization.
An attacker can exploit this vulnerability by tricking an authenticated user’s browser into making a crafted request to specific URLs with certain parameters. This can be achieved through cross-site scripting (XSS) attacks or by enticing victims to click on malicious links. Successful exploitation results in the execution of functions with the privileges of the authenticated user.
Solution
To mitigate this vulnerability, apply the correction provided in the Security Note. Ensure that your system is updated with the latest support packages as listed in the note.
CVSS
Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P
References
- SAP Note 888889 regarding automatic checks using RSECNOTE (outdated)
Affected components
- SAP_BASIS: Versions 620 to 640
- SAP_BASIS: Versions 700 to 702
- SAP_BASIS: Versions 710 to 730
- SAP_BASIS: Version 731
Full note on SAP: SAP Support Launchpad note 1728500
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
