SAP security note 1592256, “Unauthorized use of application functions in CRM”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can execute functions in CRM-MKT-ISM, CRM-ISE, CRM-MD-PCT, CRM-ISA, CRM-ANA-PS, and CRM-MD-PRO without authentication and authorization. This vulnerability allows unauthorized access and manipulation of critical CRM functionalities.
Solution
- Obsolete BSP Applications: The following BSP applications are obsolete as of several releases. SAP has updated them to enhance security, and they should no longer be used: CRM_MKTISM_TEST, ICSS_CONSUM_REG, COM_PCAT_IMSD_REPL_SHOW, CRM_ISA_AGENT, CRM_KPI_DEMO, COM_BSP_IO_MAP, CRM_PRODUCT_GETLIST.
- Prerequisite Notes: Refer to SAP Note 1520324 and SAP Note 1551982 for additional information and instructions. Implementing the corrections from these notes is a prerequisite for applying SAP Note 1592256.
- Implement Correction Instructions: Follow the correction instructions provided in this note. This will create the report
BSP_XSRF_PARAM_CRM_VARIOUSin your system. - Execute the Report: Run the report
BSP_XSRF_PARAM_VARIOUSand specify a transport request number when prompted. This action will activate XSRF protection for the adapted BSP applications.
Reason and prerequisites
CRM-MKT-ISM, CRM-ISE, CRM-MD-PCT, CRM-ISA, CRM-ANA-PS, and CRM-MD-PRO execute certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a specific URL and parameters, the function is executed with the user’s rights. This can be achieved through cross-site scripting (XSS) attacks or by presenting a deceptive link to the victim.
Affected components
- BBPCRM 500
- BBPCRM 520
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
Full note on SAP: SAP Support Launchpad note 1592256
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
