SAP Security Note
High priority
SAP security note 1660926, "Unauthorized modification of displayed content in CRM CM", is a program error note released on 08.05.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
CRM Content Management can be exploited by an attacker to modify displayed application content without authorization. Additionally, attackers may obtain authentication information from other legitimate users.
Solution
Implement the correction provided in this SAP Note.
Reason and prerequisites
The issue arises because CL_CRM_XML_LIST_TEMPLATES within CRM Content Management does not sufficiently encode input parameters. This results in a reflected cross-site scripting vulnerability, allowing attackers to:
- Deface or modify displayed content non-permanently.
- Steal authentication information, enabling impersonation of users, including administrators, thereby compromising the application’s security.
CVSS
Score 0
References
- 1669624 – SAP CRM 2005 – SP Stack 20
- 1642592 – SAP Enhancement Package 1 for SAP CRM 7.0 SP-Stack 07- RIN
Affected components
- BBPCRM: Versions 500, 520, 600, 700, 701, 702, 712
Full note on SAP: SAP Support Launchpad note 1660926
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
