Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update 1 to security note 1744747, SAP security note 1754772

SAP Note 1754772

SAP security note 1754772, "Update 1 to security note 1744747". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Security note 1744747 has been rereleased with additional workarounds addressing stored cross-site scripting (XSS) vulnerabilities in the CRM-IPC and CRM-ISA-TEC components.

Solution

This update includes Java corrections for E-Commerce and Web Channel. To apply the fix:

References

Affected components

  • SAP-CRMJAV (Versions 7.0, 7.01, 7.02, 7.30, 7.31, 7.32)
  • SAP-CRMWEB
  • SAP-SHRWEB
  • SAP-SHRJAV
  • SAP-CRMAPP
  • SAP-SHRAPP

Full note on SAP: SAP Support Launchpad note 1754772

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More