Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification in BSP application in CRM-IC-EMS, SAP security note 1679963

SAP Note 1679963

SAP security note 1679963, "Unauthorized modification in BSP application in CRM-IC-EMS". Below are the symptom and SAP recommended solution.

Description

Symptom

Unauthorized modification of application content. Potential theft of user authentication information.

Solution

Apply SAP Security Note 1679963 or import the necessary changes via the relevant support package to address the cross-site scripting issue.

Reason and prerequisites

BSP Pages within CRM-IC-EMS do not adequately encode OUTPUT parameters, leading to a cross-site scripting (XSS) vulnerability. This flaw can be exploited to steal authentication data, allowing attackers to impersonate users and gain unauthorized access.

Full note on SAP: SAP Support Launchpad note 1679963

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More