Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Untrusted XML input parsing possible in CRM-ISA, SAP security note 2244346

SAP Note 2244346
Medium priority

SAP security note 2244346, "Untrusted XML input parsing possible in CRM-ISA", is a program error note released on January 19, 2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Internet Sales
CategoryProgram error
PriorityCorrection with medium priority
StatusReleased for Customer
Released onJanuary 19, 2016

Description

Symptom

A malicious user can modify an XML-based request to include XML content that is then parsed locally. This could allow a malicious user to perform a denial of service (DoS) on the parsing system, disclose local data that is returned in the response to the malicious request, or access further network-located resources accessible from the parsing system.

Solution

This note contains Java Corrections for E-Commerce / Web Channel. For further information about installing Java Patches, consult SAP Note 877887. Information about the patch strategy can be found in SAP Note 1546959.

References

Affected components

  • CRM-ISA
  • CRM-ISE

Full note on SAP: SAP Support Launchpad note 2244346

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More