SAP security note 1864915, "Potential information disclosure relating to CRM-ISA-BBS". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can discover information relating to Web Channel Business-to-Business web shops’ order details in CRM-ISA-BBS. This information could be used to allow the attacker to specialize their attacks against the Web Channel Business-to-Business web shop and CRM-ISA-BBS.
Solution
This note contains Java correction(s) for E-Commerce and Web Channel.
- Apply the Support Package patch level attached to this note.
- For more information about applying Java patches, refer to Note 877887.
- See Note 1546959 for information about the patch strategy.
Reason and prerequisites
Information such as order details can be discovered using CRM-ISA-BBS. This information may be used by an attacker to further target the Web Channel Business-to-Business web shop.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
References
- 1546959 – Patch strategies for SAP E-Commerce solutions
- 877887 – Installing Patches for CRM Java Components and FSCM BD
Affected components
- SAP-CRMJAV: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733
- SAP-CRMWEB: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733
- SAP-SHRWEB: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733
- SAP-SHRJAV: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733
- SAP-CRMAPP: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733
- SAP-SHRAPP: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733
Full note on SAP: SAP Support Launchpad note 1864915
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



