Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modific. of displ.content in CRM_TBOX_UPLOAD, SAP security note 1490225

SAP Note 1490225
SAP Security Note
High priority

SAP security note 1490225, "Unauthorized Modification of Displayed Content in CRM_TBOX_UPLOAD", is a program error note released on December 14, 2010. Below are the symptom and the SAP recommended solution.

ComponentCustomer Relationship Management > Internet Service > Web Forms (CRM-ISE-WBF)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

The component CRM_TBOX_UPLOAD can be abused by a malicious user, allowing unauthorized modification of displayed application content and potential theft of authentication information from other legitimate users.

Solution

Apply the note using the Note Assistant in SAP.

WarningPerform this manual pre-implementation step manually and separately in each system before you import the Note to implement. For release CRM 500, Support Package 02 must be applied before the note can be implemented.

Reason and prerequisites

Pages within the component CRM_TBOX_UPLOAD do not sufficiently encode output parameters, resulting in a reflected cross site scripting vulnerability. Exploiting this can lead to non-permanent defacement or modification of web content, and theft of users’ authentication data. Elevated privileges could lead to full application security compromise.

References

Full note on SAP: SAP Support Launchpad note 1490225

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More