High priority
SAP security note 2097534, "Code Injection Vulnerability in CRM-BF-BRF", is released on 14.04.2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP has released Security Note 2097534 addressing a critical code injection vulnerability in the CRM-BF-BRF component. This vulnerability allows attackers to execute arbitrary program code, potentially leading to unauthorized system behavior control or privilege escalation without needing legitimate credentials.
Solution
To address this vulnerability, implement the correction instructions provided in the security note. This involves:
- Applying Correction Instructions: use the Download for SNOTE to apply the necessary corrections.
- Manual Configuration Changes: perform configuration changes within the BRF transaction as detailed in the security note. Ensure users have the S_DEVELOP authorization to modify SELECT and CALL FUNCTION BRF expressions.
- Transport Changes: after implementation, transport the changes throughout your system landscape to ensure consistency across environments.
Detailed steps:
- Open the BRF application class and switch to edit mode.
- Enter CL_CRM_AUTHORIZATION_BRF in the "Authorization check" field for all relevant application classes and their leaves.
- Save the changes and repeat for any other BRF application classes.
- Ensure meta implementation classes like <IMPL> are also maintained.
- Transport the configuration changes across your system landscape.
Affected components
- Customer Relationship Management > Basic Functions > Business Rules Framework (CRM-BF-BRF)
- Customer Relationship Management > Leasing (CRM-LAM)
- Customer Relationship Management > Financial Services (CRM-IFS)
Full note on SAP: SAP Support Launchpad note 2097534
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




