Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in CRM-CHM, SAP security note 2263132

SAP Note 2263132

SAP security note 2263132, "Missing authorization check in CRM-CHM". Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.

Description

Symptom

An authenticated user can use functions of CRM-CHM to which access should be restricted. This may result in an escalation of privileges.

Solution

Missing authorization checks were implemented using the Access Control Engine (ACE). ACE is configured and managed in SPRO Customizing under: Customer Relationship Management > Basic Functions > Access Control Engine. For more information, refer to the ACE section of the SAP Customer Relationship Management Security Guide.

Affected RFC function modules:

  • CRM_BUPA_RES_CCINS_GET
  • CRM_BUPA_RES_DATA_GET
  • CRM_BUPA_RES_GLOB_GET
  • CRM_BUPA_RES_SALES_AREA_CCH
  • CRM_BUPA_RES_SALES_AREA_CCH2
  • CRM_BUPA_RES_SHIPC_GET
  • CRM_CHM_PPR_DELETE
  • CRM_CHM_PPR_MAINTAIN
  • CRM_CHM_PRP_CREATE
  • CRM_CHM_PRP_SEARCH
  • CRM_CHM_PRP_SEARCH_FOR_CHP
  • CRM_CHM_PRP_SEARCH_FOR_CUST

Reason and prerequisites

CRM-CHM does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.

Affected components

  • BBPCRM 600
  • BBPCRM 700
  • BBPCRM 701
  • BBPCRM 702
  • BBPCRM 712
  • BBPCRM 713
  • BBPCRM 714

Full note on SAP: SAP Support Launchpad note 2263132

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More