SAP Security Note
High priority
SAP security note 1490225, "Unauthorized Modification of Displayed Content in CRM_TBOX_UPLOAD", is a program error note released on December 14, 2010. Below are the symptom and the SAP recommended solution.
Description
Symptom
The component CRM_TBOX_UPLOAD can be abused by a malicious user, allowing unauthorized modification of displayed application content and potential theft of authentication information from other legitimate users.
Solution
Apply the note using the Note Assistant in SAP.
Reason and prerequisites
Pages within the component CRM_TBOX_UPLOAD do not sufficiently encode output parameters, resulting in a reflected cross site scripting vulnerability. Exploiting this can lead to non-permanent defacement or modification of web content, and theft of users’ authentication data. Elevated privileges could lead to full application security compromise.
References
Full note on SAP: SAP Support Launchpad note 1490225
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
