Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized change of displayed content in CRM-IU, SAP security note 1663788

SAP Note 1663788

SAP security note 1663788, "Unauthorized change of displayed content in CRM-IU", is a note. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCRM-IU (Customer Relationship Management > Utilities Industry)

Description

Symptom

A malicious user can exploit CRM-IU to:

  • Modify displayed application content without authorization.
  • Obtain authentication information from other users, potentially leading to impersonation and unauthorized access.

Solution

To mitigate this vulnerability:

  • Implement Corrections from Note 1582870: Ensure that all corrections specified in SAP Note 1582870 are applied to your system before proceeding.
  • Apply Correction Instructions: Follow the correction instructions relevant to your specific SAP release. These instructions can be accessed here.

Reason and prerequisites

The vulnerability arises because BSP (Business Server Page) pages within CRM-IU do not sufficiently encode input and output parameters. This deficiency results in a reflected cross-site scripting (XSS) issue, which can be exploited to:

  • Non-permanently deface or modify website content.
  • Steal users’ authentication information, leading to impersonation and potential full compromise of the application’s security.

References

Affected components

  • BBPCRM 500, 600, 700, 701, 702, 712

Full note on SAP: SAP Support Launchpad note 1663788

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More