• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Не установлено обновление Note 1510881

Главная Специалистам База уязвимостей Не установлено обновление Note 1510881

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1510881-4) SAP Support Packages (SAPKU40018, SAPKU50018, SAPKU52011, SAPKU60009, SAPKU70009, SAPKU70103)
Описание
The Utility PC-UI application executes certain functions through  referencing specific URLs. When an attacker tricks an authenticated  user's browser into making a request containing a certain URL and  specific parameters, the function is executed with the rights of the user.
If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.
Как исправить
The issue can be fixed by applying attached manual correction instruction.



------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 701 Until SAPKU70102 |
------------------------------------------------------------------------

1) Goto transaction SE80 and choose "BSP Application" within the Repository Browser.

2) Choose Application "BSP_COP_EXCEL".

3) Tick-mark the "XSRF Protection" flag on "properties" tab of the BSP.

4) Clear the field "Initial BSP".

5) Save & activate the application.

6) Repeat steps 3) to 5) for BSP Applications "BSP_GRAPHICS", "BSP_ISU_PROFILE", "BSP_POD_PROFILE", "GPI_CALL" and "OFFER_CALC_EXC".


------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 400 Until SAPKU40017 |
| Release 500 Until SAPKU50017 |
| Release 520 Until SAPKU52010 |
| Release 700 Until SAPKU70008 |
| Release 600 Until SAPKU60008 |
------------------------------------------------------------------------

1. Refer to note 1520324 for additional information and instructions. The corrections from note 1520324 are a prerequisite for implementation of this note.
2. Implement the correction instructions of this note. This will also create the report BSP_XSRF_PARAM_CRM_IU in your system.
3. Execute the report BSP_XSRF_PARAM_CRM_IU and specify when requested a corresponding transport request number. The report will fill the database table BSPTEMPXSRFSTORE with corresponding table entries for the BSP applications adapted by this note.
Ссылки