Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code injection vulnerability in CRM-ISA, SAP security note 2043404

SAP Note 2043404
SAP Security Note
HotNews

SAP security note 2043404, "Code injection vulnerability in CRM-ISA", is a note released on 28.10.2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Internet Sales > Technical Infrastructure (CRM-ISA-TEC)
PriorityHotNews
TypeSAP Security Note
StatusReleased for Customer
Released on28.10.2014

Description

Symptom

This security note addresses a critical code injection vulnerability in CRM-ISA that allows the execution of arbitrary program code without requiring legitimate user credentials. An attacker can exploit this vulnerability to control system behavior, escalate privileges, modify or delete data, alter system outputs, create new users with higher privileges, or perform denial of service attacks.

Solution

Implement the Support Package (SP) Patch Level associated with this security note. Detailed instructions for installing Java Patches can be found in SAP Note 877887. For information about the patch strategy, refer to SAP Note 1546959.

Reason and prerequisites

This vulnerability does not require a valid and authenticated user to exploit. It poses a significant risk to system security, and immediate action is recommended to apply the necessary patches.

CVSS

Score 9.3 Vector: AV:N/AC:M/AU:N/C:C/I:C/A:C

References

Affected components

  • SAP-CRMJAV 5.0 to 7.33
  • SAP-CRMWEB 5.0 to 7.33
  • SAP-SHRWEB 5.0 to 7.33
  • SAP-SHRJAV 5.0 to 7.33
  • SAP-CRMAPP 5.0 to 7.33
  • SAP-SHRAPP 5.0 to 7.33

Full note on SAP: SAP Support Launchpad note 2043404

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More