Medium priority
SAP security note 1617550, "Potential information disclosure relating to user history", is a note released on 10.01.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can discover information relating to user navigation history in the CRM Web Channel B2B application. This information could be used to allow the malicious user to tailor their attacks against the B2B web shop.
Solution
Manual steps:
- Enable Secure Cookies: ensure that HTTPS is configured for the CRM Web Channel B2B applications. Set the parameter SSLEnabled to true in the General Application Settings of the Extended Configuration Management (XCM). This parameter is located in the component b2b->b2bconfig.
- Apply Java Corrections: this note contains Java corrections for E-Commerce and Web Channel. Apply the Support Package patch level attached to this note. For more information about applying Java patches, refer to Note 877887. See Note 1546959 for information about the patch strategy.
Reason and prerequisites
Information such as the user navigation history can be discovered using an unsecured history cookie in the B2B application. This information may be used by a malicious user to further target the B2B application.
Affected components
- CRM-ISA-BBS: Customer Relationship Management > Internet Sales > Business-to-Business Sales
Full note on SAP: SAP Support Launchpad note 1617550
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
