Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1510881-4)
SAP Support Packages
(SAPKU40018, SAPKU50018, SAPKU52011, SAPKU60009, SAPKU70009, SAPKU70103)
Описание
The Utility PC-UI application executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user's browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user.
If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.
If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.
Как исправить
The issue can be fixed by applying attached manual correction instruction.
------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 701 Until SAPKU70102 |
------------------------------------------------------------------------
1) Goto transaction SE80 and choose "BSP Application" within the Repository Browser.
2) Choose Application "BSP_COP_EXCEL".
3) Tick-mark the "XSRF Protection" flag on "properties" tab of the BSP.
4) Clear the field "Initial BSP".
5) Save & activate the application.
6) Repeat steps 3) to 5) for BSP Applications "BSP_GRAPHICS", "BSP_ISU_PROFILE", "BSP_POD_PROFILE", "GPI_CALL" and "OFFER_CALC_EXC".
------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 400 Until SAPKU40017 |
| Release 500 Until SAPKU50017 |
| Release 520 Until SAPKU52010 |
| Release 700 Until SAPKU70008 |
| Release 600 Until SAPKU60008 |
------------------------------------------------------------------------
1. Refer to note 1520324 for additional information and instructions. The corrections from note 1520324 are a prerequisite for implementation of this note.
2. Implement the correction instructions of this note. This will also create the report BSP_XSRF_PARAM_CRM_IU in your system.
3. Execute the report BSP_XSRF_PARAM_CRM_IU and specify when requested a corresponding transport request number. The report will fill the database table BSPTEMPXSRFSTORE with corresponding table entries for the BSP applications adapted by this note.
------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 701 Until SAPKU70102 |
------------------------------------------------------------------------
1) Goto transaction SE80 and choose "BSP Application" within the Repository Browser.
2) Choose Application "BSP_COP_EXCEL".
3) Tick-mark the "XSRF Protection" flag on "properties" tab of the BSP.
4) Clear the field "Initial BSP".
5) Save & activate the application.
6) Repeat steps 3) to 5) for BSP Applications "BSP_GRAPHICS", "BSP_ISU_PROFILE", "BSP_POD_PROFILE", "GPI_CALL" and "OFFER_CALC_EXC".
------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 400 Until SAPKU40017 |
| Release 500 Until SAPKU50017 |
| Release 520 Until SAPKU52010 |
| Release 700 Until SAPKU70008 |
| Release 600 Until SAPKU60008 |
------------------------------------------------------------------------
1. Refer to note 1520324 for additional information and instructions. The corrections from note 1520324 are a prerequisite for implementation of this note.
2. Implement the correction instructions of this note. This will also create the report BSP_XSRF_PARAM_CRM_IU in your system.
3. Execute the report BSP_XSRF_PARAM_CRM_IU and specify when requested a corresponding transport request number. The report will fill the database table BSPTEMPXSRFSTORE with corresponding table entries for the BSP applications adapted by this note.
Ссылки