SAP security note 1674849, "Unauthorized modification in BSP application in CRM-IC-CHA", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
- Unauthorized modification of application content.
- Potential theft of authentication information through cross-site scripting (XSS).
Solution
Apply this SAP Note or import the changes via the relevant support package to address the vulnerability.
Reason and prerequisites
- BSP Pages (SESSION_BUFFERED_FRAME.HTM, SPELLCHECKER.HTM) within CRM-IC-CHA do not sufficiently encode output parameters.
- This insufficient encoding results in a cross-site scripting vulnerability.
- An attacker can exploit this to steal session data and impersonate users, potentially compromising administrative accounts.
References
- SAP Note 1529979 – Attributes in mail form not populated in E-mail editor
- SAP Note 1611151 – Chat transcript disappears in Chat page
- SAP Note 1674849 – Unauthorized modification in BSP application in CRM-IC-CHA
Full note on SAP: SAP Support Launchpad note 1674849
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
