Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in BSP_XP, SAP security note 1496297

SAP Note 1496297

SAP security note 1496297, “Unauthorized modification of stored content in BSP_XP”, is a note. Below are the symptom, SAP recommended solution and affected software components.

ComponentCA-GTF-IC-FRW (Cross-Application Components > General Application Functions > use CRM-IC (Interaction Center WebClient) > use CRM-IC-FRW (Framework))

Description

Symptom

The vulnerability allows unauthorized modification of stored content within the BSP_XP application, leading to potential security breaches such as unauthorized data access and session hijacking.

Solution

For CRM releases based on WEBCUIF 7.0 to WECBUIF 7.0 Enhancement Package 1, follow the attached correction instructions.

For older releases based on SAP_ABA 7.0, perform the following steps:

  • Execute Transaction SICF to Disable Access to BSP_XP: enter "BSP_XP" in the Service Name field and execute the search; in the search results, right-click on the "BSP_XP" entry and deactivate it if it is still active.
  • Execute Transaction SE80 to Delete the BSP_XP Application: select "BSP Application" from the dropdown menu, enter BSP_XP, and proceed with the deletion.

Reason and prerequisites

The BSP_XP application has a stored cross-site scripting vulnerability. This allows attackers to permanently alter displayed content on a website, embed malicious scripts that execute automatically, and steal authentication information. An attacker with access to session data can impersonate users, including administrators, thereby compromising the application’s security comprehensively.

Affected components

  • WEBCUIF 700: Up to SAPK-70008INWEBCUIF
  • WEBCUIF 701: Up to SAPK-70101INWEBCUIF
  • WEBCUIF 730: Without Support Packages

Full note on SAP: SAP Support Launchpad note 1496297

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More