Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized change of displayed contents in CRM_ITIC, SAP security note 1484709

SAP Note 1484709
SAP Security Note
High priority

SAP security note 1484709, "Unauthorized change of displayed contents in CRM_ITIC", is a program error note released on 10.08.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCRM-IT-BTX
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on10.08.2010
LanguageEnglish

Description

Symptom

By manipulating CRM_ITIC_ADJ/SESSION_BUFFERED_FRAME.HTM, an attacker can change displayed data of another user without authorization and may also be able to access their authorization data.

Solution

Implement the attached corrections.

Reason and prerequisites

Reflected cross-site scripting can be triggered due to inadequate output coding. As a result, the content of a web page can be manipulated when a manipulated link is called, for example.

An attacker can use reflected cross-site scripting to steal the logon information of the current session of a victim. The attacker can then use this information to impersonate the victim to the server and use the application with the same rights as the compromised user.

If the target of the attack is a user with administrative rights, all of the application data may be compromised as a result.

References

Affected components

  • BBPCRM: Versions 500, 520, 600, 700, 701

Full note on SAP: SAP Support Launchpad note 1484709

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More