SAP security note 1554676, “Unauthorized use of application functions in CRM planning”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can execute functions in CRM planning without authentication and authorization.
Solution
SAP NetWeaver BW 7.00
- Import Support Package 26 for SAP NetWeaver BW 7.00 (SAPKW70026) into your BW system.
- The Support Package will be available once Note 1524896 with the short text “SAPBWNews NW BW 7.0 ABAP SP26” is released.
SAP NetWeaver BW 7.01 (SAP NW BW7.0 EnhP 1)
- Import Support Package 09 for SAP NetWeaver BW 7.01 (SAPKW70109) into your BW system.
- The Support Package will be available once Note 1369296 with the short text “SAPBINews NW7.01 BW ABAP SP09” is released.
SAP NetWeaver BW 7.02 (SAP NW BW7.0 EnhP 2)
- Import Support Package 08 for SAP NetWeaver BW 7.02 (SAPKW70208) into your BW system.
- The Support Package will be available once SAP Note 1510975 with the short text “Preliminary Version SAPBWNews NW BW 7.02 ABAP SP08” is released.
SAP NetWeaver BW 7.11
- Import Support Package 07 for SAP NetWeaver BW 7.11 (SAPKW71107) into your BW system.
- The Support Package will be available once SAP Note 1510976 with the short text “Preliminary Version SAPBINews NW7.11 BW ABAP SP7” is released.
SAP NetWeaver BW 7.30
- Import Support Package 03 for SAP NetWeaver BW 7.30 (SAPKW73003) into your BW system.
- The Support Package will be available once SAP Note 1538941 with the short text “SAPBWNews NW7.30 BW ABAP SP03” is released.
Reason and prerequisites
The CRM-MKT-MPL component in BW-PLA-BPS executes certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. This can be achieved through a cross-site scripting (XSS) attack or by presenting a deceptive link to the victim.
Full note on SAP: SAP Support Launchpad note 1554676
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



