SAP security note 1516348, "XSRF Vulnerability in Digital Asset Management", is a program error note released on 23.03.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A Cross-Site Request Forgery (XSRF) vulnerability has been identified in the Digital Asset Management BSP applications. A malicious user can exploit this vulnerability to trigger specific functionalities without proper authentication and authorization. This can be achieved by tricking an authenticated user's browser into making unintended requests, potentially leading to unauthorized actions being performed with the user's privileges.
Affected BSP Applications:
- CRM_DAM_APPLOG
- CRM_DAM_AQ
- CRM_DAM_AT_ADM
- CRM_DAM_CONFIRM
- CRM_DAM_FR_AQ
- CRM_DAM_IR_AQ
- CRM_DAM_LINK_BO
- CRM_DAM_LI_ADM
- CRM_DAM_LI_AQ
- CRM_DAM_MT_ADM
- CRM_DAM_PRD_AQ
- CRM_DAM_SNGL_UL
- CRM_DAM_TAX_ADM
- CRM_DAM_VAL_HLP
Solution
Refer to SAP Note 1520324 for additional information and instructions. The corrections from this note must be implemented before applying this note.
For CRM Releases 5.0, 5.2, 6.0 (CRM2007), and 7.0: implement the correction instructions, which will create the report BSP_XSRF_PARAM_CRM_DAM_BSP in your system. Run BSP_XSRF_PARAM_CRM_DAM_BSP and provide a transport request number when prompted; this will populate the BSPTEMPXSRFSTORE database table with the necessary entries for the affected BSP applications.
For CRM Release 7.01: after implementing the correction instructions, manually activate the XSRF Protection checkbox within each of the affected BSP applications listed above. The XSRF Protection checkbox can be found within the Properties tab of each BSP application.
References
Affected components
- CRM 5.0
- CRM 5.2
- CRM 6.0 (CRM2007)
- CRM 7.0
- CRM 7.01
Full note on SAP: SAP Support Launchpad note 1516348
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



