SAP Security Note
Medium priority
SAP security note 1489430, "Supplier selfregistration: missing checks of user input data", is a note released on 12.10.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The registration of a Potential Supplier in the SRM ROS (Registration of Supplier) application could be exploited by a malicious user. This user might modify displayed application content and cause prolonged application running times by forcing loops based on user input (e.g., processing of attachment file names or lists of purchasing categories) into an excessive number of iterations.
Solution
Implement the attached correction instructions or import the corresponding support package.
Reason and prerequisites
This issue arises from a program error where loops based on user input do not have a reasonable upper limit for iterations.
Affected components
- SAP SRM 5.0
- SAP SRM 5.5
- SAP SRM 6.0
- SAP SRM 7.0
- SAP SRM 7.01
Full note on SAP: SAP Support Launchpad note 1489430
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
