The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://erpscan.io/advisories/erpscan-17-036-csrf-sap-java-crm/ | |
https://blogs.sap.com/2017/07/11/sap-security-patch-day-july-2017/ | issue tracking vendor advisory |