SAP Security Note
High priority
SAP security note 1592837, "Dangerous File Inclusion in CRM Web Channel", is a program error note released on 10.01.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Web Channel applications contain code that potentially allows a malicious user to include unexpected web content that changes the program’s behaviour.
Solution
This note contains Java correction(s) for E-Commerce and Web Channel.
- For more information about applying Java patches, refer to Note 877887.
- See Note 1546959 for information about the patch strategy.
Reason and prerequisites
File inclusion vulnerabilities occur because the path of the included file is controlled by unvalidated user input.
CVSS
Score 0
References
This note refers to
Affected components
- SAP-CRMISA 4.0_640
- SAP-CRMJAV 5.0
- SAP-CRMJAV 6.0
- SAP-CRMJAV 700
- SAP-CRMJAV 701
- SAP-CRMJAV 730
- SAP-CRMWEB 5.0
- SAP-CRMWEB 6.0
- SAP-CRMWEB 700
- SAP-CRMWEB 701
- SAP-CRMWEB 730
- SAP-SHRWEB 5.0
- SAP-SHRWEB 6.0
- SAP-SHRWEB 700
- SAP-SHRWEB 701
- SAP-SHRWEB 730
- SAP-SHRJAV 5.0
- SAP-SHRJAV 6.0
- SAP-SHRJAV 700
- SAP-SHRJAV 701
- SAP-SHRJAV 730
- SAP-CRMAPP 5.0
- SAP-CRMAPP 6.0
- SAP-CRMAPP 700
- SAP-CRMAPP 701
- SAP-CRMAPP 730
- SAP-SHRAPP 5.0
- SAP-SHRAPP 6.0
- SAP-SHRAPP 700
- SAP-SHRAPP 701
- SAP-SHRAPP 730
Full note on SAP: SAP Support Launchpad note 1592837
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




