• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Не установлено обновление Note 1514717

Главная Специалистам База уязвимостей Не установлено обновление Note 1514717

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1514717-1) SAP Support Packages (SAPK-40013INCRMIS, SAPKU40018, SAPKU50018, SAPKU52011, SAPKU60009, SAPKU70009, SAPKU70103)
Описание
The above mentioned BSP applications execute certain functions through  referencing specific URLs. When an attacker tricks an authenticated  user#s browser into making a request containing a certain URL and  specific parameters, the function is executed with the rights of the user.
If present, the attacker may use a Cross Site Scripting attack to  trigger the exploit, or use an approach in which a link to click is presented to the victim.
Как исправить
Please pay attention to the manual pre and post implementation steps attached to the note. For CRM 7.01 just implement the attached corrections. For lower releases manual steps are needed.



------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 701 Until SAPKU70102 |
------------------------------------------------------------------------
1. Enter transaction SE80 and edit the BSP Application BBP_SUS_UM.
a) Mark the checkbox for "XSRF Protection".
b) Save and activate your changes.
2. Enter transaction SE80 and edit the BSP Application BBP_SUS_WORKER.
a) Mark the checkbox for "XSRF Protection".
b) Save and activate your changes.
3. Enter transaction SE80 and edit the BSP Application CRM_BSP_PSD_CHM.
a) Mark the checkbox for "XSRF Protection".
b) Save and activate your changes.
4. Enter transaction SE80 and edit the BSP Application CRM_SEND_SCREEN.
a) Mark the checkbox for "XSRF Protection".
b) Save and activate your changes.
------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 500 Until SAPKU50017 |
| Release 520 Until SAPKU52010 |
| Release 700 Until SAPKU70008 |
| Release 600 Until SAPKU60008 |
------------------------------------------------------------------------

Refer to note 1520324 for additional information and instructions. The corrections from note 1520324 are a prerequisite for implementation of this note.

Implement the correction instructions of this note. This will also create the report BSP_XSRF_PARAM_CRM_MISC_3 in your system.


------------------------------------------------------------------------
|Manual Pre-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 400 Until SAPKU40017 |
------------------------------------------------------------------------

Refer to note 1520324 for additional information and instructions. The corrections from note 1520324 are a prerequisite for implementation of this note.

Implement the correction instructions of this note. Please create the reports BSP_XSRF_PARAM_CRM_MISC_3_400A and BSP_XSRF_PARAM_CRM_MISC_3_400B in your system.

Both should be maintained as "SAP standard production report".

Report BSP_XSRF_PARAM_CRM_MISC_3_400A should be created in package CRM_CHM_CM_PRT_F+R. The second report should go to
package CRM_EMAIL.

If the correction can not be applied via SNOTE, please check the correction instructions attached for CRM 4.0. There is one for BBPCRM, another one for CRMIS. The CRM version contains a small change to BSP application BBP_SUS_UM. Apply this as described and insert the programm code for the reports.


------------------------------------------------------------------------
|Manual Post-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 500 Until SAPKU50017 |
| Release 520 Until SAPKU52010 |
| Release 700 Until SAPKU70008 |
| Release 600 Until SAPKU60008 |
------------------------------------------------------------------------

These is only needed for CRM 7.0 and lower.

1. Execute the reports BSP_XSRF_PARAM_CRM_MISC_3 and specify when requested a corresponding transport request number. The report will fill the database table BSPTEMPXSRFSTORE with corresponding table entries for the BSP applications adapted by this note.

2. Remark: If you have already upgraded your system to a basis support package containing note 1520324 (please check the corresponding SP in this note), the BSP meta data repository will be filled with the right data instead of the table entries in BSPTEMPXSRFSTORE as mentioned beforehand.



------------------------------------------------------------------------
|Manual Post-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component BBPCRM BBP / CRM |
| Release 400 Until SAPKU40017 |
------------------------------------------------------------------------

These is only needed for CRM 7.0 and lower.

1. Execute the reports BSP_XSRF_PARAM_CRM_MISC_3_400A and BSP_XSRF_PARAM_CRM_MISC_3_400B and specify when requested a corresponding transport request number. The report will fill the database table BSPTEMPXSRFSTORE with corresponding table entries for the BSP applications adapted by this note.

2. Remark: If you have already upgraded your system to a basis support package containing note 1520324 (please check the corresponding SP in this note), the BSP meta data repository will be filled with the right data instead of the table entries in BSPTEMPXSRFSTORE as mentioned beforehand.
Ссылки