SAP security note 1682611, “Unauthorized modification in BSP application in CRM-IPS-BTX”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit CRM-IPS-BTX to modify displayed application content without authorization. This vulnerability may also allow the attacker to obtain authentication information from other legitimate users, potentially leading to impersonation and unauthorized access to sensitive data.
Solution
To mitigate this vulnerability, apply SAP Security Note 1682611 or import the necessary changes via the relevant support package. Ensure that all affected BSP pages are updated to properly encode output parameters, thereby preventing unauthorized content modifications and securing user authentication data.
Reason and prerequisites
The vulnerability exists because certain BSP Pages (e.g., MultiFundingEdit.htm, MultiFundingView.htm, MainView.htm, WebRequestEdit.htm, WebRequestOverview.htm) within CRM-IPS-BTX do not sufficiently encode output parameters. This lack of proper encoding results in a cross-site scripting issue, enabling attackers to steal user authentication information and impersonate users, including administrators, thereby compromising the security of the application.
Affected components
- BBPCRM 520
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
- BBPCRM 702
- BBPCRM 712
Full note on SAP: SAP Support Launchpad note 1682611
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




