Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code Injection vulnerability in SAP Internet Sales, SAP security note 2626762

SAP Note 2626762

SAP security note 2626762, "Code Injection Vulnerability in SAP Internet Sales", is a note. Below are the symptom, CVSS score, SAP recommended solution, references and the affected software components.

Description

Symptom

SAP Internet Sales is using a vulnerable version of Apache Struts. The MultiPageValidator implementation in Apache Struts 1.1 through 1.3.10 allows under certain conditions a remote attacker to bypass intended access restrictions via a modified page parameter. This vulnerability is identified as CVE-2015-0899. An attacker could thereby control the behavior of the application.

Solution

This SAP note contains Java Correction(s) for E-Commerce / Web Channel with additional input validation to prevent this vulnerability.

  • Implement the SP Patch Level attached to this note.
  • For further information about installing Java Patches, consult SAP note 877887.
  • Information about the patch strategy can be found in SAP note 1546959.

CVSS

Score 7.5 / 10 Vector: AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References

Affected components

  • SAP-CRMJAV: Versions 730, 731, 732, 733, 754
  • SAP-CRMWEB: Versions 730, 731, 732, 733, 754
  • SAP-SHRWEB: Versions 730, 731, 732, 733, 754
  • SAP-SHRJAV: Versions 730, 731, 732, 733, 754
  • SAP-CRMAPP: Versions 730, 731, 732, 733, 754
  • SAP-SHRAPP: Versions 730, 731, 732, 733, 754

Full note on SAP: SAP Support Launchpad note 2626762

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More