Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification in BSP in CRM-IC-SCR, SAP security note 1675411

SAP Note 1675411
SAP Security Note
High priority

SAP security note 1675411, "Unauthorized modification in BSP in CRM-IC-SCR", is a program error note released on May 8, 2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Interaction Center WebClient > Scripting (CRM-IC-SCR)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released onMay 8, 2012
LanguageEnglish

Description

Symptom

  • Unauthorized modification of application content
  • Potential theft of authentication information via Cross-site Scripting (XSS)

Solution

Apply this security note or import the changes via the relevant support package associated with your system’s software components.

Reason and prerequisites

BSP Pages within CRM-IC-SCR do not sufficiently encode OUTPUT parameters, resulting in a cross-site scripting issue. Affected files include:

  • CRMCMP_SCR SCRLEAD.HTM
  • CRMCMP_SCR SCRTRANSCRIPT.HTM
  • CRMCMP_SCR SCRURL.HTM

Affected components

  • SAP_ABA 700
  • BBPCRM 500
  • BBPCRM 520
  • BBPCRM 600
  • BBPCRM 700
  • BBPCRM 701
  • BBPCRM 702
  • BBPCRM 712

Full note on SAP: SAP Support Launchpad note 1675411

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More