SAP security note 1496679, “Unauthorized modification of content in IC Context area code”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
The IC Context Area can be abused by a malicious user to modify displayed application content without authorization. This could allow an attacker to obtain authentication information from other legitimate users.
Solution
Apply the correction instructions provided in this note to mitigate the vulnerability. Detailed instructions can be found here.
Reason and prerequisites
HTM pages in the BSP Application CRMCMP_IC_FRAME do not sufficiently encode parameters, resulting in a Local Cross-Site Scripting (XSS) issue. This vulnerability allows attackers to modify displayed content on a website. Parameters passed to a web page are processed and embedded into the page on the client via JavaScript. An attacker exploiting this vulnerability could impersonate users and access information with the same rights as the target user. If an administrator is impersonated, the application’s security could be fully compromised.
Full note on SAP: SAP Support Launchpad note 1496679
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
