Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification in BSP in CRM-IC, SAP security note 1675484

SAP Note 1675484
SAP Security Note
High priority

SAP security note 1675484, "Unauthorized modification in BSP in CRM-IC", is a note released on January 13, 2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCRM-IC-FRW
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onJanuary 13, 2014

Description

Symptom

CRM-IC can be abused by a malicious user, allowing them to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.

Vulnerability: Cross-site scripting (XSS) in BSP Pages within CRM-IC.

Affected Files:

  • CRMCMP_IC_FRAME BROADCAST_POPUP.HTM
  • CRMCMP_IC_FRAME CRMCMP_IC_FRAME_DEBUG_PAGE.HTM
  • CRMCMP_IC_FRAME DEBUG_PAGE.HTM
  • CRMCMP_IC_FRAME MCMAIN_HEADER.HTM
  • CRMCMP_IC_FRAME SCRATCHPAD.HTM
  • CRM_IC_WS_TEST ICWebServiceTest.htm

XSS can be used to steal users' authentication information, potentially allowing impersonation of users, including administrators. This can lead to a complete compromise of the application's security.

Solution

Apply this note by importing the changes via the relevant support package or manually applying the corrections.

References

Affected components

  • BBPCRM 520
  • BBPCRM 600
  • BBPCRM 700
  • BBPCRM 701
  • BBPCRM 702
  • BBPCRM 712

Full note on SAP: SAP Support Launchpad note 1675484

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More