SAP Security Note
High priority
SAP security note 1505808, “Unauthorized Usage of Application Function in Interaction Center”, is a note released on December 14, 2010. Below are the symptom, reason and prerequisites, SAP recommended solution, references and the affected software components.
Description
Symptom
A malicious user can trigger functionality in the following BSP applications without authentication and authorization:
- CRM_IC_MDB
- ICCMP_CCS
- CRM_IC_MDB_PERS
- ICCMP_GLOBAL
- ICCMP_BT_GLOBAL
- BSP_BROADCAST
Affected ITS service:
- CCMP_RABOX
Solution
For CRM 701: Implement the related correction instructions.
For CRM 700 and earlier releases:
- Refer to Note 1520324 for additional information and instructions. Corrections from this note are prerequisites for implementing this note.
- Implement the correction instructions of this note. This creates the reports
BSP_XSRF_PARAM_CRM_IC_MDB_<release>andBSP_XSRF_PARAM_CRM_MISC_2in your system. - Execute the reports
BSP_XSRF_PARAM_CRM_IC_MDB_<release>andBSP_XSRF_PARAM_CRM_MISC_2, specifying a corresponding transport request number when prompted. This fills theBSPTEMPXSRFSTOREtable with entries for the adapted BSP applications. - If your system is already upgraded to a basis support package containing Note 1520324, the BSP metadata repository will be populated correctly, eliminating the need for manual table entries.
Reason and prerequisites
The Interaction Center application executes certain functions through specific URLs. An attacker can trick an authenticated user’s browser into making requests with these URLs and parameters, executing functions with the user’s privileges. This can be leveraged through:
- Cross Site Scripting (XSS) attacks
- Malicious links presented to the victim
References
Affected components
- BBPCRM (500, 520, 600, 700, 701)
Full note on SAP: SAP Support Launchpad note 1505808
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



