SAP Security Note
SAP security note 1590175, "Unauthorized use of application functions in CRM-MKT-DAM", was released on 11.09.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can trigger functionality in the following BSP applications without authentication and authorization: CRM_DAM_MUPL, CRM_DAM_DELETE, CRM_DAM_AS_ADM (applicable for Releases CRM 5.0, CRM 5.2, CRM 6.0 (CRM2007), CRM 7.0, CRM 7.01, and CRM 7.02).
Solution
Prerequisites and Post Actions:
- Refer to Notes 1520324 and 1551982: these notes provide additional information and instructions. Implementing the corrections from these notes is a prerequisite for this note.
- Applicable Releases: CRM 5.0, CRM 5.2, CRM 6.0 (CRM2007), CRM 7.0, CRM 7.01, and CRM 7.02.
- Implement the Correction Instructions: this will create the report CRM_BSP_XSRF_PARAM_DAM_BSP_2 in your system. The report is valid for the specified releases. Note that the report differs for CRM 7.01 and CRM 7.02 due to the unavailability of one BSP.
- Execute the Report CRM_BSP_XSRF_PARAM_DAM_BSP_2: specify the requested transport request number when prompted. This report will populate the database table BSPTEMPXSRFSTORE with entries for the adapted BSP applications.
Reason and prerequisites
The mentioned BSP applications execute certain functions through specific URLs. An attacker can trick an authenticated user’s browser into making a request with specific URLs and parameters, executing functions with the user’s privileges. This can be achieved through Cross Site Scripting (XSS) attacks or by presenting malicious links to the victim.
References
Full note on SAP: SAP Support Launchpad note 1590175
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
