Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to user history, SAP security note 1617550

SAP Note 1617550
Medium priority

SAP security note 1617550, "Potential information disclosure relating to user history", is a note released on 10.01.2012. Below are the symptom, SAP recommended solution and the affected software components.

PriorityCorrection with medium priority
StatusReleased for Customer
Released on10.01.2012

Description

Symptom

A malicious user can discover information relating to user navigation history in the CRM Web Channel B2B application. This information could be used to allow the malicious user to tailor their attacks against the B2B web shop.

Solution

Manual steps:

  • Enable Secure Cookies: ensure that HTTPS is configured for the CRM Web Channel B2B applications. Set the parameter SSLEnabled to true in the General Application Settings of the Extended Configuration Management (XCM). This parameter is located in the component b2b->b2bconfig.
  • Apply Java Corrections: this note contains Java corrections for E-Commerce and Web Channel. Apply the Support Package patch level attached to this note. For more information about applying Java patches, refer to Note 877887. See Note 1546959 for information about the patch strategy.

Reason and prerequisites

Information such as the user navigation history can be discovered using an unsecured history cookie in the B2B application. This information may be used by a malicious user to further target the B2B application.

Affected components

  • CRM-ISA-BBS: Customer Relationship Management > Internet Sales > Business-to-Business Sales

Full note on SAP: SAP Support Launchpad note 1617550

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More