Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauth. modification of stored content in Interaction Center, SAP security note 1497951

SAP Note 1497951

SAP security note 1497951, "Unauthorized Modification of Stored Content in Interaction Center", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

This security note addresses a vulnerability in the ERMS E-mail Workbench and the Agent Inbox E-Mail Editor within the Interaction Center. A malicious user could exploit this vulnerability to modify application content without authorization, persist the modified content, and potentially obtain authentication information from other legitimate users.

  • Stored Cross Site Scripting (XSS): Allows attackers to permanently alter website content, embed malicious scripts, and steal user authentication data.
  • Authentication Theft: Can be used to impersonate users, potentially leading to unauthorized access to sensitive information.
  • Administrative Compromise: If an administrator’s account is targeted, it may result in a full compromise of the application’s security.

Solution

To mitigate this vulnerability, apply the following corrective measures:

  • Sanitize HTML Content: Ensure that your e-mail infrastructure can secure/sanitize HTML emails with active content (e.g., JavaScript) before they are sent to the Interaction Center. Activate filtering on the e-mail server to sanitize incoming HTML content.
  • Deactivate HTML Email Display: If sanitization is not feasible, deactivate the display of HTML emails in the Interaction Center.
  • Configure ERMS Rules: Set up an ERMS rule to handle (e.g., delete) incoming HTML emails. Inform senders automatically that HTML mails cannot be viewed. Recognize HTML mails by the E-Mail Document Type ‘HTM’ in the ERMS rule modeler and apply the necessary customizations.

References

Affected components

  • BBPCRM 500
  • BBPCRM 520
  • BBPCRM 600
  • BBPCRM 700
  • BBPCRM 701
  • WEBCUIF 701
  • CRMIS 400

Full note on SAP: SAP Support Launchpad note 1497951

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More