Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

XSRFJavaAdopt API-PSI Utility Customer E-Services, SAP security note 1516177

SAP Note 1516177

SAP security note 1516177, "XSRFJava:Adopt API-PSI Utility Customer E-Services", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can trigger functionality in SAP_UCES without authentication and authorization.

Solution

Please refer to SAP Note 1509214. All instructions provided in that note for FSCM_BD also apply to SAP_UCES. Specifically, replace "bd" with "bdisu" for SAP_UCES and ensure that changes to JSP files in the isuExtensions folder are implemented.

Reason and prerequisites

SAP_UCES executes certain functions by referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the user’s rights. Additionally, attackers may use Cross Site Scripting (XSS) to trigger the exploit or present a clickable link to the victim.

References

Affected components

  • SAP-UCES: 1.0, 6.0, 6.02, 6.04, 6.05

Full note on SAP: SAP Support Launchpad note 1516177

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More