Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

XSRF Vulnerability in Digital Asset Management, SAP security note 1516348

SAP Note 1516348SAP Security NoteHigh priority

SAP security note 1516348, "XSRF Vulnerability in Digital Asset Management", is a program error note released on 23.03.2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Marketing > Digital Asset Management (CRM-MKT-DAM)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version8
StatusReleased for Customer
Released on23.03.2012
LanguageEnglish

Description

Symptom

A Cross-Site Request Forgery (XSRF) vulnerability has been identified in the Digital Asset Management BSP applications. A malicious user can exploit this vulnerability to trigger specific functionalities without proper authentication and authorization. This can be achieved by tricking an authenticated user's browser into making unintended requests, potentially leading to unauthorized actions being performed with the user's privileges.

Affected BSP Applications:

  • CRM_DAM_APPLOG
  • CRM_DAM_AQ
  • CRM_DAM_AT_ADM
  • CRM_DAM_CONFIRM
  • CRM_DAM_FR_AQ
  • CRM_DAM_IR_AQ
  • CRM_DAM_LINK_BO
  • CRM_DAM_LI_ADM
  • CRM_DAM_LI_AQ
  • CRM_DAM_MT_ADM
  • CRM_DAM_PRD_AQ
  • CRM_DAM_SNGL_UL
  • CRM_DAM_TAX_ADM
  • CRM_DAM_VAL_HLP

Solution

Refer to SAP Note 1520324 for additional information and instructions. The corrections from this note must be implemented before applying this note.

For CRM Releases 5.0, 5.2, 6.0 (CRM2007), and 7.0: implement the correction instructions, which will create the report BSP_XSRF_PARAM_CRM_DAM_BSP in your system. Run BSP_XSRF_PARAM_CRM_DAM_BSP and provide a transport request number when prompted; this will populate the BSPTEMPXSRFSTORE database table with the necessary entries for the affected BSP applications.

For CRM Release 7.01: after implementing the correction instructions, manually activate the XSRF Protection checkbox within each of the affected BSP applications listed above. The XSRF Protection checkbox can be found within the Properties tab of each BSP application.

WarningThese manual steps must be performed separately in each system after importing the Note.

References

Affected components

  • CRM 5.0
  • CRM 5.2
  • CRM 6.0 (CRM2007)
  • CRM 7.0
  • CRM 7.01

Full note on SAP: SAP Support Launchpad note 1516348

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More