Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Dangerous File Inclusion in CRM Web Channel, SAP security note 1592837

SAP Note 1592837
SAP Security Note
High priority

SAP security note 1592837, "Dangerous File Inclusion in CRM Web Channel", is a program error note released on 10.01.2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCRM-ISA (Customer Relationship Management > Internet Sales)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on10.01.2012
LanguageEnglish

Description

Symptom

Web Channel applications contain code that potentially allows a malicious user to include unexpected web content that changes the program’s behaviour.

Solution

This note contains Java correction(s) for E-Commerce and Web Channel.

  • For more information about applying Java patches, refer to Note 877887.
  • See Note 1546959 for information about the patch strategy.

Reason and prerequisites

File inclusion vulnerabilities occur because the path of the included file is controlled by unvalidated user input.

CVSS

Score 0

References

Affected components

  • SAP-CRMISA 4.0_640
  • SAP-CRMJAV 5.0
  • SAP-CRMJAV 6.0
  • SAP-CRMJAV 700
  • SAP-CRMJAV 701
  • SAP-CRMJAV 730
  • SAP-CRMWEB 5.0
  • SAP-CRMWEB 6.0
  • SAP-CRMWEB 700
  • SAP-CRMWEB 701
  • SAP-CRMWEB 730
  • SAP-SHRWEB 5.0
  • SAP-SHRWEB 6.0
  • SAP-SHRWEB 700
  • SAP-SHRWEB 701
  • SAP-SHRWEB 730
  • SAP-SHRJAV 5.0
  • SAP-SHRJAV 6.0
  • SAP-SHRJAV 700
  • SAP-SHRJAV 701
  • SAP-SHRJAV 730
  • SAP-CRMAPP 5.0
  • SAP-CRMAPP 6.0
  • SAP-CRMAPP 700
  • SAP-CRMAPP 701
  • SAP-CRMAPP 730
  • SAP-SHRAPP 5.0
  • SAP-SHRAPP 6.0
  • SAP-SHRAPP 700
  • SAP-SHRAPP 701
  • SAP-SHRAPP 730

Full note on SAP: SAP Support Launchpad note 1592837

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More