Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauth. usage of application function in Interaction Center, SAP security note 1505808

SAP Note 1505808
SAP Security Note
High priority

SAP security note 1505808, “Unauthorized Usage of Application Function in Interaction Center”, is a note released on December 14, 2010. Below are the symptom, reason and prerequisites, SAP recommended solution, references and the affected software components.

ComponentCustomer Relationship Management > Interaction Center WebClient > Framework
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released onDecember 14, 2010
LanguageEnglish

Description

Symptom

A malicious user can trigger functionality in the following BSP applications without authentication and authorization:

  • CRM_IC_MDB
  • ICCMP_CCS
  • CRM_IC_MDB_PERS
  • ICCMP_GLOBAL
  • ICCMP_BT_GLOBAL
  • BSP_BROADCAST

Affected ITS service:

  • CCMP_RABOX

Solution

For CRM 701: Implement the related correction instructions.

For CRM 700 and earlier releases:

  • Refer to Note 1520324 for additional information and instructions. Corrections from this note are prerequisites for implementing this note.
  • Implement the correction instructions of this note. This creates the reports BSP_XSRF_PARAM_CRM_IC_MDB_<release> and BSP_XSRF_PARAM_CRM_MISC_2 in your system.
  • Execute the reports BSP_XSRF_PARAM_CRM_IC_MDB_<release> and BSP_XSRF_PARAM_CRM_MISC_2, specifying a corresponding transport request number when prompted. This fills the BSPTEMPXSRFSTORE table with entries for the adapted BSP applications.
  • If your system is already upgraded to a basis support package containing Note 1520324, the BSP metadata repository will be populated correctly, eliminating the need for manual table entries.

Reason and prerequisites

The Interaction Center application executes certain functions through specific URLs. An attacker can trick an authenticated user’s browser into making requests with these URLs and parameters, executing functions with the user’s privileges. This can be leveraged through:

  • Cross Site Scripting (XSS) attacks
  • Malicious links presented to the victim

References

Affected components

  • BBPCRM (500, 520, 600, 700, 701)

Full note on SAP: SAP Support Launchpad note 1505808

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More