Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3467377
was released on
09.07.2024 and deals with
"[Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)" within SAP CRM UI.
We advice you to follow the instructions, to resolve
server-side request forgery (ssrf)
missing authorization check
cross-site scripting (xss)
with a
medium potential for exploitation
in component CA-WUI-UI.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
This note concerns four vulnerabilities in SAP CRM (WebClient UI). The first cross-site scripting vulnerability allows an unauthenticated attacker to embed a malicious script in a URL link, which is then executed in the attacker's browser. The second cross-site scripting vulnerability is caused by Custom CSS support option not sufficiently encoding user input. In addition, a server-side request forgery vulnerability allows an authenticated attacker to enumerate HTTP endpoints on the internal network. Finally, a missing authorization check can lead to a privilege escalation of an authenticated attacker.Solution
The vulnerabilities were fixed by removing the vulnerable code.
The advisory is valid for
- S4FND 102 16
- S4FND 103 16
- S4FND 104 16
- S4FND 105 13
- S4FND 106 11
- S4FND 107 9
- S4FND 108 4
- WEBCUIF 701 11
- WEBCUIF 731 13
- WEBCUIF 746 13
- WEBCUIF 747 13
- WEBCUIF 748 14
- WEBCUIF 800 14
- WEBCUIF 801 14