SAP security note 2263132, "Missing authorization check in CRM-CHM". Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.
Description
Symptom
An authenticated user can use functions of CRM-CHM to which access should be restricted. This may result in an escalation of privileges.
Solution
Missing authorization checks were implemented using the Access Control Engine (ACE). ACE is configured and managed in SPRO Customizing under: Customer Relationship Management > Basic Functions > Access Control Engine. For more information, refer to the ACE section of the SAP Customer Relationship Management Security Guide.
Affected RFC function modules:
CRM_BUPA_RES_CCINS_GETCRM_BUPA_RES_DATA_GETCRM_BUPA_RES_GLOB_GETCRM_BUPA_RES_SALES_AREA_CCHCRM_BUPA_RES_SALES_AREA_CCH2CRM_BUPA_RES_SHIPC_GETCRM_CHM_PPR_DELETECRM_CHM_PPR_MAINTAINCRM_CHM_PRP_CREATECRM_CHM_PRP_SEARCHCRM_CHM_PRP_SEARCH_FOR_CHPCRM_CHM_PRP_SEARCH_FOR_CUST
Reason and prerequisites
CRM-CHM does not contain authorization checks for verifying an authenticated user’s authorization to access some of its functions. This may result in undesired system behavior.
Affected components
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
- BBPCRM 702
- BBPCRM 712
- BBPCRM 713
- BBPCRM 714
Full note on SAP: SAP Support Launchpad note 2263132
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
