SAP security note 1497951, "Unauthorized Modification of Stored Content in Interaction Center", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses a vulnerability in the ERMS E-mail Workbench and the Agent Inbox E-Mail Editor within the Interaction Center. A malicious user could exploit this vulnerability to modify application content without authorization, persist the modified content, and potentially obtain authentication information from other legitimate users.
- Stored Cross Site Scripting (XSS): Allows attackers to permanently alter website content, embed malicious scripts, and steal user authentication data.
- Authentication Theft: Can be used to impersonate users, potentially leading to unauthorized access to sensitive information.
- Administrative Compromise: If an administrator’s account is targeted, it may result in a full compromise of the application’s security.
Solution
To mitigate this vulnerability, apply the following corrective measures:
- Sanitize HTML Content: Ensure that your e-mail infrastructure can secure/sanitize HTML emails with active content (e.g., JavaScript) before they are sent to the Interaction Center. Activate filtering on the e-mail server to sanitize incoming HTML content.
- Deactivate HTML Email Display: If sanitization is not feasible, deactivate the display of HTML emails in the Interaction Center.
- Configure ERMS Rules: Set up an ERMS rule to handle (e.g., delete) incoming HTML emails. Inform senders automatically that HTML mails cannot be viewed. Recognize HTML mails by the E-Mail Document Type ‘HTM’ in the ERMS rule modeler and apply the necessary customizations.
References
- SAP Note 1653065 – Update #1 to Security Note 1497951
- SAP Note 1617266 – Unauthorized Modification of Content in Interaction Center
Affected components
- BBPCRM 500
- BBPCRM 520
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
- WEBCUIF 701
- CRMIS 400
Full note on SAP: SAP Support Launchpad note 1497951
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




