SAP security note 1681066, "Missing virus scan in CRM-ISA during data import". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can upload files that are potentially infected with a virus. This may result in an escalation of privileges.
Solution
This note contains Java correction(s) for E-Commerce and Web Channel.
- Apply the Support Package patch level attached to this note.
- For more information about applying Java patches, refer to Note 877887.
- See Note 1546959 for information about the patch strategy.
Reason and prerequisites
CRM-ISA does not perform virus scanning when potentially polluted data is imported through input channels into the SAP system. This may result in undesired system behavior.
Side effects
This document is causing side effects: 2046746 – Missing JSESSIONMARKID in B2C-shop.
CVSS
Score 0
References
This note refers to
Affected components
- SAP-CRMJAV (5.0, 6.0, 700, 701, 702, 730, 731, 732)
- SAP-CRMWEB (5.0, 6.0, 700, 701, 702, 730, 731, 732)
- SAP-SHRWEB (5.0, 6.0, 700, 701, 702, 730, 731, 732)
- SAP-SHRJAV (5.0, 6.0, 700, 701, 702, 730, 731, 732)
- SAP-CRMAPP (5.0, 6.0, 700, 701, 702, 730, 731, 732)
- SAP-SHRAPP (5.0, 6.0, 700, 701, 702, 730, 731, 732)
Full note on SAP: SAP Support Launchpad note 1681066
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



