Skip links

Unauthorized use of application functions in CRM-ISA, SAP security note 1619202

Description

A malicious user can execute functions in CRM-ISA without authentication and authorization.

Available fix and Supported packages

  • SAP-CRMJAV | 5.0 | 5.0
  • SAP-CRMJAV | 6.0 | 6.0
  • SAP-CRMJAV | 700 | 700
  • SAP-CRMJAV | 701 | 701
  • SAP-CRMJAV | 730 | 730
  • SAP-CRMWEB | 5.0 | 5.0
  • SAP-CRMWEB | 6.0 | 6.0
  • SAP-CRMWEB | 700 | 700
  • SAP-CRMWEB | 701 | 701
  • SAP-CRMWEB | 730 | 730
  • SAP-SHRWEB | 5.0 | 5.0
  • SAP-SHRWEB | 6.0 | 6.0
  • SAP-SHRWEB | 700 | 700
  • SAP-SHRWEB | 701 | 701
  • SAP-SHRWEB | 730 | 730
  • SAP-SHRJAV | 5.0 | 5.0
  • SAP-SHRJAV | 6.0 | 6.0
  • SAP-SHRJAV | 700 | 700
  • SAP-SHRJAV | 701 | 701
  • SAP-SHRJAV | 730 | 730
  • CRM JAVA APPLICATIONS 5.0 | SP019 | 000004
  • CRM JAVA APPLICATIONS 6.0 | SP008 | 000023
  • CRM JAVA APPLICATIONS 7.0 | SP010 | 000002
  • CRM JAVA APPLICATIONS 7.01 | SP006 | 000005
  • CRM JAVA APPLICATIONS 7.30 | SP000 | 000009
  • CRM JAVA COMPONENTS 5.0 | SP019 | 000004
  • CRM JAVA COMPONENTS 6.0 | SP008 | 000023
  • CRM JAVA COMPONENTS 7.0 | SP010 | 000002
  • CRM JAVA COMPONENTS 7.01 | SP006 | 000005
  • CRM JAVA COMPONENTS 7.30 | SP000 | 000009
  • CRM JAVA WEB COMPONENTS 5.0 | SP019 | 000004
  • CRM JAVA WEB COMPONENTS 6.0 | SP008 | 000023
  • CRM JAVA WEB COMPONENTS 7.0 | SP010 | 000002
  • CRM JAVA WEB COMPONENTS 7.01 | SP006 | 000005
  • CRM JAVA WEB COMPONENTS 7.30 | SP000 | 000009
  • SAP SHARED JAVA APPLIC. 5.0 | SP019 | 000004
  • SAP SHARED JAVA APPLIC. 6.0 | SP008 | 000023
  • SAP SHARED JAVA APPLIC. 7.0 | SP010 | 000002
  • SAP SHARED JAVA APPLIC. 7.01 | SP006 | 000005
  • SAP SHARED JAVA APPLIC. 7.30 | SP000 | 000009

Affected component

    CRM-ISA
    Internet Sales

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1619202

TAGS

#Cross-site-request-forgery
#XSRF
#Internet-Sales
#isa
#ECo
#E-Commerce
#E-Commerce
#WebChannel
#Web-Channel
#CRM
#ERP
#r3
#r\3
#r/3
#ECC
#XCM
#admin
#administration
#Internet-Sales-Auctioning-via-Web-Shop
#avw
#E-Service-Complaints-and-Returns-Application
#cr_b2b
#IMS-Admin-Console
#imsadmin
#E-Service-Inspection-application
#insp_b2b
#E-Selling-User-Management
#isauseradm
#E-Commerce-Shop-Management
#shopadmin
#Collaborative-Views-Enterprise-Application
#cviews
#Entitlement-Inquiry-Enterprise-Application
#entitlementinquiry
#Web-Catalog-Administration-Enterprise-Application
#webcatadmin

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,