SAP security note 1554460, “Unauthorized use of application in CRM Portal Integration”, is a security note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The CRM portal integration could be abused by a malicious user, who can modify displayed application content without authorization.
Solution
This note contains a Java-Correction for EP / Enterprise Portal.
- Software components: BPCRMFND, BP_CRM50
- Development Component: sap.com/ep/crm/foundation/dnac
- Changed Files: dnac.jsp, portalapp.xml, DNAC.java, .dcdef
Implement the SP Patch Level attached to this note.
Reason and prerequisites
Dynamic Navigation iViews within the CRM portal integration execute certain functions by referencing specific URLs. When a malicious user tricks an authenticated user’s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the authenticated user. As a result, the content of those iViews could be modified.
CVSS
Score 0
References
This note refers to
Affected components
- BP_CRM50, version 6.0
- CRMFND, version 700
- CRMFND, version 701
- CRMFND, version 730
Full note on SAP: SAP Support Launchpad note 1554460
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
