Medium priority
SAP security note 1554295, “Potential Information Disclosure Relating to CRM EP”, is a program error note released on 08.11.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can discover information relating to the CRM portal integration who uses the CRMFND software component. This information could be used to allow the malicious user to specialize their attacks against the CRM portal integration and the CRMFND software component.
Solution
This note contains a Java-Correction for EP / Enterprise Portal.
- Software Components: BPCRMFND, BP_CRM50
- Development Component: sap.com/ep/crm/foundation/header
- Changed File: crmCSscript.jsp
Implement the SP Patch Level attached to this note.
Reason and prerequisites
Information such as the communication between the portal and CRM can be discovered using CRMFND. This information may be used by a malicious user to further target the CRM portal integration.
References
Affected components
- BP_CRM50 (6.0)
- CRMFND (700, 701, 731)
Full note on SAP: SAP Support Launchpad note 1554295
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
