Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification in ITS-Service in SCM-APO-CA-COP, SAP security note 1677486

SAP Note 1677486

SAP security note 1677486, "Unauthorized modification in ITS-Service in SCM-APO-CA-COP", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

A malicious user can exploit SCM-APO-CA-COP to modify application content without proper authorization and obtain authentication details from other users.

Solution

To mitigate this vulnerability, apply the manual correction instructions provided in this note or import the changes via the relevant support package. Additionally, ensure that the corrections from SAP Notes 1621946 and 1488500 are implemented, as they are prerequisites for the effectiveness of this fix.

Reason and prerequisites

ITS Service components (AMON, AMON_STATIST, CLPBID, CLPPROMCAL, CLPSDP) within SCM-APO-CA-COP do not sufficiently encode output parameters, resulting in a cross-site scripting (XSS) vulnerability.

References

Full note on SAP: SAP Support Launchpad note 1677486

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More