Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Multiple vulnerabilities in SAP ERP Stakeholder Relationship Management, SAP security note 2426076

SAP Note 2426076
SAP Security Note
Medium priority

SAP security note 2426076, "Multiple vulnerabilities in SAP ERP Stakeholder Relationship Management", is a program error note released on 11.04.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFinancials > Strategic Enterprise Management > Stakeholder Relationship Management (FIN-SEM-SRM)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version8
StatusReleased for Customer
Released on11.04.2017
LanguageEnglish

Description

Symptom

Denial of Service: The SEM-SRM SMTP inbound class, when assigned inappropriately in customizing of Inbound Exists (SO50), can allow an attacker to prevent legitimate users from accessing a service by crashing or flooding the service.

Impacts of Denial of Service Vulnerability:

  • Long response delays and service interruptions, degrading service quality for legitimate users.
  • Direct impact on availability.
  • Unexpected business partner creation without proper authentication.

Solution

  • Do Not Assign: Avoid assigning class CL_USC_CONTACT_SERVICES in SO50 unless you are using the SEM-SRM application.
  • Apply Correction: Implement the attached code correction with SNOTE or apply the relevant support package.
  • Post-Implementation: After applying the correction, the class will only handle inbound processes belonging to the customized known SRM recipient contacts.

Reason and prerequisites

The issue can only occur when the SRM inbound exit class is used in transaction SO50 and assigned to a recipient email address unrelated to the SRM application.

CVSS

Score 5.3 Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected components

  • S4CORE 101
  • SEM-BW (versions 320 to 800)

Full note on SAP: SAP Support Launchpad note 2426076

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More