SAP security note 1663788, "Unauthorized change of displayed content in CRM-IU", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit CRM-IU to:
- Modify displayed application content without authorization.
- Obtain authentication information from other users, potentially leading to impersonation and unauthorized access.
Solution
To mitigate this vulnerability:
- Implement Corrections from Note 1582870: Ensure that all corrections specified in SAP Note 1582870 are applied to your system before proceeding.
- Apply Correction Instructions: Follow the correction instructions relevant to your specific SAP release. These instructions can be accessed here.
Reason and prerequisites
The vulnerability arises because BSP (Business Server Page) pages within CRM-IU do not sufficiently encode input and output parameters. This deficiency results in a reflected cross-site scripting (XSS) issue, which can be exploited to:
- Non-permanently deface or modify website content.
- Steal users’ authentication information, leading to impersonation and potential full compromise of the application’s security.
References
- SAP Note 1669624 – SAP CRM 2005 – SP Stack 20
- SAP Note 1642592 – SAP Enhancement Package 1 for SAP CRM 7.0 SP-Stack 07- RIN
- SAP Note 1582870 – ABAP XSS Escaping Support
Affected components
- BBPCRM 500, 600, 700, 701, 702, 712
Full note on SAP: SAP Support Launchpad note 1663788
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
