Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized use of application in CRM Portal Integration, SAP security note 1554460

SAP Note 1554460

SAP security note 1554460, “Unauthorized use of application in CRM Portal Integration”, is a security note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The CRM portal integration could be abused by a malicious user, who can modify displayed application content without authorization.

Solution

This note contains a Java-Correction for EP / Enterprise Portal.

  • Software components: BPCRMFND, BP_CRM50
  • Development Component: sap.com/ep/crm/foundation/dnac
  • Changed Files: dnac.jsp, portalapp.xml, DNAC.java, .dcdef

Implement the SP Patch Level attached to this note.

Reason and prerequisites

Dynamic Navigation iViews within the CRM portal integration execute certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. As a result, the content of those iViews could be modified.

CVSS

Score 0

References

Affected components

  • BP_CRM50, version 6.0
  • CRMFND, version 700
  • CRMFND, version 701
  • CRMFND, version 730

Full note on SAP: SAP Support Launchpad note 1554460

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More