Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification in BSP appl. in CRM-ANA-MKT-CLV, SAP security note 1675350

SAP Note 1675350

SAP security note 1675350, "Unauthorized modification in BSP appl. in CRM-ANA-MKT-CLV." Below are the symptom and SAP recommended solution.

Description

Symptom

A malicious user can exploit CRM-ANA-MKT-CLV to:

  • Modify displayed application content without proper authorization.
  • Steal authentication information from legitimate users.

Solution

Apply SAP Security Note 1675350 or import the changes via the relevant support package. After applying the correction, the affected BSP Pages will be deactivated.

Reason and prerequisites

BSP Pages (RSAN_CLV_BSP, CLTV) within CRM-ANA-MKT-CLV do not sufficiently encode OUTPUT parameters, resulting in a Cross-Site Scripting (XSS) vulnerability.

  • Stealing Authentication Information: Attackers can obtain session data, allowing them to impersonate users.
  • User Impersonation: Unauthorized access to user accounts, potentially with the same privileges.
  • Full Security Compromise: If an administrator’s account is compromised, the entire application security can be breached.

References

Full note on SAP: SAP Support Launchpad note 1675350

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More