Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of SOAP-Processor 620, SAP security note 1728500

SAP Note 1728500

SAP security note 1728500, “Unauthorized use of SOAP-Processor 620”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP has released Security Note 1728500 addressing a critical vulnerability in the SOAP Processor 620 (ICF Service for /sap/bc/soap/rfc). This vulnerability allows attackers to execute functions without proper authentication and authorization.

An attacker can exploit this vulnerability by tricking an authenticated user’s browser into making a crafted request to specific URLs with certain parameters. This can be achieved through cross-site scripting (XSS) attacks or by enticing victims to click on malicious links. Successful exploitation results in the execution of functions with the privileges of the authenticated user.

Solution

To mitigate this vulnerability, apply the correction provided in the Security Note. Ensure that your system is updated with the latest support packages as listed in the note.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

References

Affected components

  • SAP_BASIS: Versions 620 to 640
  • SAP_BASIS: Versions 700 to 702
  • SAP_BASIS: Versions 710 to 730
  • SAP_BASIS: Version 731

Full note on SAP: SAP Support Launchpad note 1728500

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More