SAP Security Note
High priority
SAP security note 1687426, “Unauthorized Modification in BSP in CA-GTF-IC-SCR 1 Released”, is a note released on May 8, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can exploit the vulnerability to modify displayed application content without authorization and potentially obtain authentication information from other users. This can lead to impersonation of users, including administrators, compromising the security of the entire application.
Solution
To mitigate this issue, apply Security Note 1687426 along with the following related notes:
- 1632687 – Unauthorized modification in BSP in CA-GTF-IC-SCR 2
- 1687477 – Unauthorized modification in BSP in CA-GTF-IC-SCR 3
Important: for CRM 7.0 EHP2 releases, apply the notes in the following order:
- Apply 1687426 first.
- Follow with 1632687.
- Finally, apply 1687477.
For releases below EHP2 of CRM 7.0, implementing 1687426 is sufficient as it contains all relevant changes.
References
- 1632687 – Unauthorized modification in BSP in CA-GTF-IC-SCR 2
- 1671470 – BSP: Design2008 for release 7.00 and 7.01
- 1582870 – ABAP XSS Escaping Support
- 1582867 – Security options (XSS) for ESCAPE
Full note on SAP: SAP Support Launchpad note 1687426
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
