Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application functions in DAM, SAP security note 1590223

SAP Note 1590223

SAP security note 1590223, “Unauthorized use of application functions in DAM”, is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

A malicious user can execute functions in CRM Digital Asset Management (DAM) without authentication and authorization.

Solution

  • For CRM 2007 onwards: Implement the SP Patch Level attached to this note.
  • For CRM 5.0: Please implement note 935787.

Reason and prerequisites

CRM DAM executes certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. The malicious user may use a cross-site scripting attack to do this, or they may present a link to the victim.

Full note on SAP: SAP Support Launchpad note 1590223

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More