SAP security note 1517162, "Unauthorized modification of stored content in IC E-Mail", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Interaction Center e-mail attachment viewer can be abused by a malicious user, allowing unauthorized modification of application content. This vulnerability enables attackers to persist modified content without authorization and potentially obtain authentication information from other legitimate users.
Exploiting this vulnerability allows a malicious user to perform stored cross site scripting attacks, permanently modifying displayed content on a website. This can lead to automatic rendering of malicious content without targeting individual victims. Additionally, attackers can steal authentication information such as session data, enabling user impersonation. If an administrator is impersonated, it could result in a complete compromise of the application's security.
Solution
Implement the provided correction. After applying the correction, the IC e-mail attachment viewer will prompt the browser to display a save-as dialog, allowing users to store attachments for further processing (e.g., scanning with antivirus software).
References
Affected components
- BBPCRM 520
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
Full note on SAP: SAP Support Launchpad note 1517162
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



