SAP security note 1516177, "XSRFJava:Adopt API-PSI Utility Customer E-Services", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in SAP_UCES without authentication and authorization.
Solution
Please refer to SAP Note 1509214. All instructions provided in that note for FSCM_BD also apply to SAP_UCES. Specifically, replace "bd" with "bdisu" for SAP_UCES and ensure that changes to JSP files in the isuExtensions folder are implemented.
Reason and prerequisites
SAP_UCES executes certain functions by referencing specific URLs. When an attacker tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the user’s rights. Additionally, attackers may use Cross Site Scripting (XSS) to trigger the exploit or present a clickable link to the victim.
References
- SAP Note 1597549 – Unauthorized modification of displayed content in FSCM_BD
- SAP Note 1509214 – Unauthorized usage of application functionality in FSCM_BD
- SAP Note 1450166 – Unauthorized usage of application functionality
Affected components
- SAP-UCES: 1.0, 6.0, 6.02, 6.04, 6.05
Full note on SAP: SAP Support Launchpad note 1516177
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



