Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security fixes for SRM DUET PUMA scenario, SAP security note 1426388

SAP Note 1426388

SAP security note 1426388, "Security fixes for SRM DUET PUMA scenario". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

As part of an original requirement for the DUET PUMA scenario, SRM provides a function module, which is called by the DUET server to retrieve budget information for a given shopping cart. Based on an initial limitation for the DUET server, this function module had to provide importing parameters. However, this creates a security issue where a malicious user can abuse this parameter and see budget information for which they are not authorized.

The malicious user can call this function module and fill the parameter with a value that grants them the authorization to view budget information, even if they do not have the proper authorization. This unauthorized access should not be possible.

Solution

Please implement the attached corrections provided in the SAP Note.

Reason and prerequisites

This issue is classified as a program error.

References

Affected components

  • SAP SRM 5.0
  • SAP SRM 6.0
  • SAP SRM 7.0

Full note on SAP: SAP Support Launchpad note 1426388

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More