SAP Security Note
HotNews
SAP security note 2043404, "Code injection vulnerability in CRM-ISA", is a note released on 28.10.2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses a critical code injection vulnerability in CRM-ISA that allows the execution of arbitrary program code without requiring legitimate user credentials. An attacker can exploit this vulnerability to control system behavior, escalate privileges, modify or delete data, alter system outputs, create new users with higher privileges, or perform denial of service attacks.
Solution
Implement the Support Package (SP) Patch Level associated with this security note. Detailed instructions for installing Java Patches can be found in SAP Note 877887. For information about the patch strategy, refer to SAP Note 1546959.
Reason and prerequisites
This vulnerability does not require a valid and authenticated user to exploit. It poses a significant risk to system security, and immediate action is recommended to apply the necessary patches.
CVSS
Score 9.3 Vector: AV:N/AC:M/AU:N/C:C/I:C/A:C
References
Affected components
- SAP-CRMJAV 5.0 to 7.33
- SAP-CRMWEB 5.0 to 7.33
- SAP-SHRWEB 5.0 to 7.33
- SAP-SHRJAV 5.0 to 7.33
- SAP-CRMAPP 5.0 to 7.33
- SAP-SHRAPP 5.0 to 7.33
Full note on SAP: SAP Support Launchpad note 2043404
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
