Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of content in CRM IC, SAP security note 1644756

SAP Note 1644756

SAP security note 1644756, "Unauthorized Modification in CRM IC – Stored XSS Vulnerability", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Some functions in the CRM Interaction Center that utilize the BTF editor can be exploited by a malicious user. This allows unauthorized modification of application content, persistence of the altered content without proper authorization, and potential access to authentication information of other legitimate users.

Solution

Implement the attached correction instructions to ensure that content processed by the BTF editor is properly filtered. If filtering is not feasible, the content will be removed to prevent unauthorized modifications.

Reason and prerequisites

Exploiting certain functions within the CRM Interaction Center’s BTF editor can lead to a stored cross-site scripting (XSS) vulnerability. This vulnerability enables attackers to:

  • Permanently modify website content, embedding malicious content that executes automatically without targeting individual victims.
  • Steal authentication information, such as session data, from other users.
  • Impersonate users, including administrators, potentially compromising the entire application’s security.

Affected components

  • BBPCRM Versions: 500, 520, 600, 700, 701, 702, 712

Full note on SAP: SAP Support Launchpad note 1644756

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More