SAP security note 1657210, “Unauthorized Modification of Displayed Content in Web.Req. Toolbox”, is a note released on May 8, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
The CRM Web Request toolbox components can be exploited by malicious users to alter displayed content without authorization. This may lead to the theft of authentication information from other users, enabling impersonation and unauthorized access with the same privileges as the targeted user. If an administrator’s credentials are compromised, the entire application’s security could be severely undermined.
Solution
To mitigate this vulnerability, SAP recommends applying Security Note 1657210 or importing the necessary changes through the relevant support package. The primary fix involves updating the HTMLB-design for the CRM_TBOX_UPLOAD application from CLASSIC or DESIGN2002 to DESIGN2003. This change ensures better compatibility and security without impacting the application’s functionality.
Reason and prerequisites
The vulnerability stems from insufficient encoding of output parameters within the CRM Web Request toolbox components. Specifically, the lack of proper encoding allows XSS attacks, which can be leveraged to steal session data and authentication details. This issue affects multiple versions of the CRM components, making it imperative to address promptly to prevent potential exploitation.
Full note on SAP: SAP Support Launchpad note 1657210
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
