Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauth. usage of application function in Interaction Center, SAP security note 1512106

SAP Note 1512106

SAP security note 1512106, “Unauthorized Usage of Application Function in Interaction Center”, is a note. Below is the security information published by SAP for this note.

Description

A vulnerability in SAP CRM Interaction Center (IC) allows malicious users to trigger certain functionalities in Interaction Center BSP applications without proper authentication and authorization. This could lead to unauthorized actions performed with the user's rights.

Affected components

  • Cross-Application Components > General Application Functions > CRM-IC (Interaction Center WebClient) > CRM-IC-BRO (Broadcast Messaging)

Solution

To address this vulnerability, follow these steps:

1. Prerequisites:

  • Implement the corrections from SAP Note 1520324 as they are prerequisites for this fix.

2. Implement Corrections:

  • Apply the correction instructions provided in SAP Note 1512106. This will create the necessary reports: BSP_XSRF_PARAM_CRM_BM and BSP_XSRF_PARAM_CRM_MISC.

3. Execute Reports:

  • Run the reports BSP_XSRF_PARAM_CRM_BM and BSP_XSRF_PARAM_CRM_MISC. When prompted, specify a transport request number. These reports will populate the BSPTEMPXSRFSTORE table with the required entries for the affected BSP applications.

4. Manual Corrections:

  • Apply the manual corrections to the BSP applications as detailed in the correction instructions of the note.

Full note on SAP: SAP Support Launchpad note 1512106

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More