Medium priority
SAP security note 1531958, "Potential disclosure of persisted data in AP IPC", is a note released on 04.09.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit AP IPC by using specially crafted inputs to modify database commands, potentially retrieving additional persisted data from the system. This vulnerability is caused by an SQL injection flaw where unscrupulous manipulation of SQL statements allows unauthorized data access.
Solution
- Apply the Correction Instruction: download and install the attached ZIP file BBPCRM40.zip which contains the authorization object IPC_DB_RFC and related structures. Follow SAP Note 480180 and SAP Note 13719 for installation instructions. Ensure the fix is applied to all systems with the software component SAP_AP 700 regardless of AP IPC usage.
- Manual Implementation for BBPCRM: for the BBPCRM component, manually implement the correction steps as the fix includes authorization objects in the SAP namespace. After installing the ZIP file, verify that the relevant objects have been updated according to the correction instructions.
- User Role Configuration: if using IPC 4.0, create appropriate user roles and profiles using transaction PFCG. Add the new authorization object IPC_DB_RFC and set the activity value to 16. Assign this role and profile to the IPC DB user configured in the IPC Administrator tool for backend system database access. Ensure that other users do not receive this new role. Additionally, the IPC Administrator user must have the authorization to display relevant pricing customizing and master data tables using authorization object S_TABU_DIS with field ACTVT = 3.
References
- SAP Note 1720999 – Update 1 to Security Note 1531958
- SAP Note 1699572 – PME to use FM /SLC(C|E)/EXTRACT_DATA instead of EXTRACT_DATA
Affected components
- Application Platform > Pricing and Condition Technique > Pricing (AP-PRC-PR)
- Customer Relationship Management > Internet Pricing and Configurator (CRM-IPC)
- Application Platform > Tax Engine (AP-TTE)
- Application Platform > Configuration Engine (SCE): Product Configuration (AP-CFG)
Full note on SAP: SAP Support Launchpad note 1531958
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
