Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing authorization check in CRM-ISA-BBS, SAP security note 1925908

SAP Note 1925908

SAP security note 1925908, "Missing authorization check in CRM-ISA-BBS". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An authenticated user can use functions of CRM-ISA-BBS to which access should be restricted. This may result in an escalation of privileges.

Solution

This note contains Java Corrections for E-Commerce / Web Channel.

  • Implement the SP Patch Level attached to this note.
  • For further information about installing Java Patches, consult note 877887.
  • Information about the patch strategy can be found in note 1546959.

Reason and prerequisites

CRM-ISA-BBS does not contain authorization checks for verifying an authenticated user’s authorization to access certain functions. This may lead to undesired system behavior.

CVSS

Score 3.6 Vector: AV:N/AC:H/AU:S/C:P/I:P/A:N

References

Affected components

  • SAP-CRMJAV (5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
  • SAP-CRMWEB (5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
  • SAP-SHRWEB (5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
  • SAP-SHRJAV (5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
  • SAP-CRMAPP (5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
  • SAP-SHRAPP (5.0, 6.0, 7.0, 700, 701, 702, 730, 731, 732, 733)

Full note on SAP: SAP Support Launchpad note 1925908

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More