SAP security note 1673038, "SUS – Unauthorized Modification in BSP Application SRMSUS", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 1673038 addresses a critical vulnerability in the SRM-SUS application component that allows unauthorized modification of displayed application content through a Cross-Site Scripting (XSS) attack. This vulnerability can enable malicious users to steal authentication information from legitimate users, potentially compromising the entire application by impersonating administrators.
Solution
- Implement prerequisite notes: ensure SAP Note 1582870 (ABAP XSS Escaping Support) and SAP Note 1582867 (Security options (XSS) for ESCAPE) are implemented using SNOTE before proceeding.
- Apply the correction: use SNOTE to apply the correction instructions provided in SAP Note 1673038, or alternatively implement the corresponding support package.
Reason and prerequisites
- Unauthorized modification of application content.
- Theft of authentication information, leading to session hijacking.
- Potential full compromise of application security if an administrator is impersonated.
References
- 1508969 – Unauthorized usage of application functionality in SRM
- 1003820 – Supplier cannot be registered
- 1032573 – FormofAddr field mandatory in userselfreg.htm page
- 1411659 – Security fixes for SRM SUS, Vendor Evaluation, SRM ROS
- 1579382 – Incomplete error messages during self-registration
- 1597931 – XSRF Protection for the stateless BSP application
- 1682054 – Unauthorized modification of displayed content in SRM-SUS
- 1582870 – ABAP XSS Escaping Support
- 1582867 – Security options (XSS) for ESCAPE
Affected components
- SRM_SERVER 500
- SRM_SERVER 550
- SRM_SERVER 600
- SRM_SERVER 700
- SRM_SERVER 701
- SRM_SERVER 702
Full note on SAP: SAP Support Launchpad note 1673038
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



