Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SUS Unauthorized modification in BSP application SRMSUS, SAP security note 1673038

SAP Note 1673038

SAP security note 1673038, "SUS – Unauthorized Modification in BSP Application SRMSUS", is a note. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSRM-SUS (Supplier Relationship Management > Supplier Self-Services)

Description

Symptom

SAP Security Note 1673038 addresses a critical vulnerability in the SRM-SUS application component that allows unauthorized modification of displayed application content through a Cross-Site Scripting (XSS) attack. This vulnerability can enable malicious users to steal authentication information from legitimate users, potentially compromising the entire application by impersonating administrators.

Solution

  1. Implement prerequisite notes: ensure SAP Note 1582870 (ABAP XSS Escaping Support) and SAP Note 1582867 (Security options (XSS) for ESCAPE) are implemented using SNOTE before proceeding.
  2. Apply the correction: use SNOTE to apply the correction instructions provided in SAP Note 1673038, or alternatively implement the corresponding support package.

Reason and prerequisites

  • Unauthorized modification of application content.
  • Theft of authentication information, leading to session hijacking.
  • Potential full compromise of application security if an administrator is impersonated.

References

Affected components

  • SRM_SERVER 500
  • SRM_SERVER 550
  • SRM_SERVER 600
  • SRM_SERVER 700
  • SRM_SERVER 701
  • SRM_SERVER 702

Full note on SAP: SAP Support Launchpad note 1673038

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More