Medium priority
SAP security note 2244346, "Untrusted XML input parsing possible in CRM-ISA", is a program error note released on January 19, 2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can modify an XML-based request to include XML content that is then parsed locally. This could allow a malicious user to perform a denial of service (DoS) on the parsing system, disclose local data that is returned in the response to the malicious request, or access further network-located resources accessible from the parsing system.
Solution
This note contains Java Corrections for E-Commerce / Web Channel. For further information about installing Java Patches, consult SAP Note 877887. Information about the patch strategy can be found in SAP Note 1546959.
References
- SAP Note 2253493 – XMLHardener
- SAP Note 2241912 – Web Channel Wrapper for XML Hardener Library
- SAP Note 1546959 – Patch strategies for SAP E-Commerce solutions
- SAP Note 877887 – Installing Patches for CRM Java Components and FSCM BD
Affected components
- CRM-ISA
- CRM-ISE
Full note on SAP: SAP Support Launchpad note 2244346
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




