SAP security note 1861907, "Potential Information Disclosure Relating to CRM-ISA-TEC", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Information related to E-Commerce/Web Channel configurations can be disclosed.
Solution
Apply the Support Package patch attached to this note. For more information on applying Java patches, refer to Note 877887. Additionally, see Note 1546959 for patch strategies related to SAP E-Commerce solutions.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:P/I:N/A:N
References
- Note 1546959 – Patch Strategies for SAP E-Commerce Solutions
- Note 877887 – Installing Patches for CRM Java Components and FSCM BD
Affected components
- CRM JAVA COMPONENTS: Versions 5.0, 6.0, 7.0, 7.01, 7.02, 7.30, 7.31, 7.32, 7.33
- CRM WEB COMPONENTS: Same versions
- SAP SHARED JAVA/WEB COMPONENTS, APPLIC., COMP.: Same versions
Full note on SAP: SAP Support Launchpad note 1861907
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
