SAP security note 1925908, "Missing authorization check in CRM-ISA-BBS". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of CRM-ISA-BBS to which access should be restricted. This may result in an escalation of privileges.
Solution
This note contains Java Corrections for E-Commerce / Web Channel.
- Implement the SP Patch Level attached to this note.
- For further information about installing Java Patches, consult note 877887.
- Information about the patch strategy can be found in note 1546959.
Reason and prerequisites
CRM-ISA-BBS does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may lead to undesired system behavior.
CVSS
Score 3.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:N
References
- Patch strategies for SAP E-Commerce solutions (#1546959)
- Installing Patches for CRM Java Components and FSCM BD (#877887)
- Side effect: 1929623 – Behavior of the login procedure in E-Commerce/Web Channel applications updated
Affected components
- SAP-CRMJAV (5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
- SAP-CRMWEB (5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
- SAP-SHRWEB (5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
- SAP-SHRJAV (5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
- SAP-CRMAPP (5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
- SAP-SHRAPP (5.0, 6.0, 7.0, 700, 701, 702, 730, 731, 732, 733)
Full note on SAP: SAP Support Launchpad note 1925908
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
