SAP security note 2626762, "Code Injection Vulnerability in SAP Internet Sales", is a note. Below are the symptom, CVSS score, SAP recommended solution, references and the affected software components.
Description
Symptom
SAP Internet Sales is using a vulnerable version of Apache Struts. The MultiPageValidator implementation in Apache Struts 1.1 through 1.3.10 allows under certain conditions a remote attacker to bypass intended access restrictions via a modified page parameter. This vulnerability is identified as CVE-2015-0899. An attacker could thereby control the behavior of the application.
Solution
This SAP note contains Java Correction(s) for E-Commerce / Web Channel with additional input validation to prevent this vulnerability.
- Implement the SP Patch Level attached to this note.
- For further information about installing Java Patches, consult SAP note 877887.
- Information about the patch strategy can be found in SAP note 1546959.
CVSS
Score 7.5 / 10 Vector: AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
References
- CVE-2015-0899
- SAP Note 1546959 – Patch strategies for SAP E-Commerce solutions
- SAP Note 877887 – Installing Patches for CRM Java Components and FSCM BD
- SAP Note 2651424 – IPC parameter is not allowed in an action form
Affected components
- SAP-CRMJAV: Versions 730, 731, 732, 733, 754
- SAP-CRMWEB: Versions 730, 731, 732, 733, 754
- SAP-SHRWEB: Versions 730, 731, 732, 733, 754
- SAP-SHRJAV: Versions 730, 731, 732, 733, 754
- SAP-CRMAPP: Versions 730, 731, 732, 733, 754
- SAP-SHRAPP: Versions 730, 731, 732, 733, 754
Full note on SAP: SAP Support Launchpad note 2626762
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



