Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of content in gATP pop-up, SAP security note 1654492

SAP Note 1654492
High priority

SAP security note 1654492, “Unauthorized modification of content in gATP pop-up”, is a program error note released on May 8, 2012. Below are the symptom and SAP recommended solution.

ComponentCustomer Relationship Management > Business Transactions > Basic Functions for Business Transactions > Availability Check
CategoryProgram error
PriorityCorrection with high priority
StatusReleased for Customer
Released onMay 8, 2012

Description

Symptom

The global availability to promise (gATP) pop-up in the CRM WebClient UI can be abused by an attacker, allowing them to modify displayed application content without authorization, and potentially obtain authentication information from other legitimate users.

Solution

Implement the source code corrections provided in your release. Ensure that all relevant SAP support packages are up to date.

Reason and prerequisites

The gATP pop-up within the CRM WebClient UI component BTGATP does not sufficiently encode the URL for displaying ATP results, resulting in a reflected cross-site scripting issue. An attacker can exploit this vulnerability to:

  • Non-permanently deface or modify displayed content on the website.
  • Steal another user’s authentication information, such as session data.
  • Impersonate users, potentially compromising application security, especially if an administrator is targeted.

Full note on SAP: SAP Support Launchpad note 1654492

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More