SAP security note 1426388, "Security fixes for SRM DUET PUMA scenario". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
As part of an original requirement for the DUET PUMA scenario, SRM provides a function module, which is called by the DUET server to retrieve budget information for a given shopping cart. Based on an initial limitation for the DUET server, this function module had to provide importing parameters. However, this creates a security issue where a malicious user can abuse this parameter and see budget information for which they are not authorized.
The malicious user can call this function module and fill the parameter with a value that grants them the authorization to view budget information, even if they do not have the proper authorization. This unauthorized access should not be possible.
Solution
Please implement the attached corrections provided in the SAP Note.
Reason and prerequisites
This issue is classified as a program error.
References
This note refers to
Affected components
- SAP SRM 5.0
- SAP SRM 6.0
- SAP SRM 7.0
Full note on SAP: SAP Support Launchpad note 1426388
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
