Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in CRM-MKT-DAM, SAP security note 1590175

SAP Note 1590175
SAP Security Note

SAP security note 1590175, "Unauthorized use of application functions in CRM-MKT-DAM", was released on 11.09.2012. Below are the symptom and SAP recommended solution.

ComponentCustomer Relationship Management > Marketing > Digital Asset Management
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on11.09.2012

Description

Symptom

A malicious user can trigger functionality in the following BSP applications without authentication and authorization: CRM_DAM_MUPL, CRM_DAM_DELETE, CRM_DAM_AS_ADM (applicable for Releases CRM 5.0, CRM 5.2, CRM 6.0 (CRM2007), CRM 7.0, CRM 7.01, and CRM 7.02).

Solution

Prerequisites and Post Actions:

  • Refer to Notes 1520324 and 1551982: these notes provide additional information and instructions. Implementing the corrections from these notes is a prerequisite for this note.
  • Applicable Releases: CRM 5.0, CRM 5.2, CRM 6.0 (CRM2007), CRM 7.0, CRM 7.01, and CRM 7.02.
  • Implement the Correction Instructions: this will create the report CRM_BSP_XSRF_PARAM_DAM_BSP_2 in your system. The report is valid for the specified releases. Note that the report differs for CRM 7.01 and CRM 7.02 due to the unavailability of one BSP.
  • Execute the Report CRM_BSP_XSRF_PARAM_DAM_BSP_2: specify the requested transport request number when prompted. This report will populate the database table BSPTEMPXSRFSTORE with entries for the adapted BSP applications.

Reason and prerequisites

The mentioned BSP applications execute certain functions through specific URLs. An attacker can trick an authenticated user’s browser into making a request with specific URLs and parameters, executing functions with the user’s privileges. This can be achieved through Cross Site Scripting (XSS) attacks or by presenting malicious links to the victim.

References

This note refers to

  • 1551982 – Cross-site request forgery protection for stateless
  • 1520324 – Advance creation of XSRF information

Full note on SAP: SAP Support Launchpad note 1590175

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More