SAP security note 1597425, “Unauth. usage of functions in IC_BASE founded applications”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trigger functionality in Interaction Center BSP applications without proper authentication and authorization. This vulnerability allows unauthorized access by tricking an authenticated user’s browser into making specific requests, potentially executing functions with the user’s rights.
Solution
Implement the attached correction instructions or upgrade to the next support package level according to your system version.
Affected components
- CRM-IC-FRW (Customer Relationship Management > Interaction Center WebClient > Framework), version 700
Full note on SAP: SAP Support Launchpad note 1597425
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
