SAP Security Note
High priority
SAP security note 1674616, “Unauthorized modification of content in transaction launcher”, is a program error note released on July 5, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
When the CRM Transaction Launcher is used to launch backend applications, a malicious user can:
- Modify application content
- Persist the modified content without authorization
- Potentially obtain authentication information from other legitimate users
This vulnerability allows for unauthorized actions such as embedding malicious content or stealing user authentication data.
Solution
Implement the correction instructions provided in the note to address the vulnerability.
Reason and prerequisites
Applications utilizing the CRM Transaction Launcher are vulnerable to stored XSS attacks. This allows for the permanent modification of displayed content on a website, enabling malicious users to embed content that is automatically rendered without needing to target individual victims. Additionally, attackers can steal authentication information, leading to user impersonation and potential full compromise of the application’s security.
Affected components
- SAP_ABA: 700
- CRMUIF: 600
- PI: 2004_1_470 to 2004_1_500
- WEBCUIF: 700, 701, 730, 731, 746
Full note on SAP: SAP Support Launchpad note 1674616
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




