SAP Security Note
HotNews
SAP security note 625135, "CRM ABAP solution: Display orders of other users possible", was released on October 8, 2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Due to a program error, an internet user can display all sales orders in the system:
- Java-based SAP Internet Sales Application: affects the B2C scenario.
- ITS-based SAP Internet Sales Application: affects both B2C and B2B scenarios if the
~multiinstanceservicesparameter is set to '0' in the service file (isas of2c.srvc for isas of2b or global), as detailed in Note 416209.
Solution
The issue is addressed by implementing corrections that prevent the display of sales documents not belonging to the logged-in internet user. The solution is included in the following support packages:
- CRM 2.0b: Support Package 30 and later
- CRM 2.0c: Support Package 23 and later
- CRM 3.0: Support Package 16 and later
- CRM 3.1: Support Package 6 and later
- CRM 4.0: Support Package 2 and later
Alternatively, you can implement the attached corrections provided in the SAP Note.
Reason and prerequisites
The vulnerability is caused by a program error that fails to restrict access to sales documents based on the logged-in user.
References
Affected components
- CRM-ISA (Customer Relationship Management > Internet Sales)
- BBPCRM 20B to 20C
- BBPCRM 300 to 300
- BBPCRM 310 to 310
- BBPCRM 400 to 400
Full note on SAP: SAP Support Launchpad note 625135
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
