Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized mod. of displayed content in CRM-ISE-WBF, SAP security note 1659560

SAP Note 1659560
High

SAP security note 1659560, "Unauthorized Modification of Displayed Content in CRM-ISE-WBF", is a note released on May 8, 2012. Below are the symptom and SAP recommended solution.

ComponentCRM-ISE-WBF (Customer Relationship Management > Internet Service > Web Forms)
PriorityHigh
StatusReleased for Customer
Released onMay 8, 2012

Description

Symptom

BSP applications of the component CRM-ISE-WBF can be exploited by malicious users to modify displayed application content without authorization. This vulnerability allows attackers to potentially obtain authentication information from legitimate users, leading to impersonation and unauthorized access to sensitive information. Specifically, the issue stems from insufficient encoding of output parameters, resulting in a Cross-Site Scripting (XSS) vulnerability.

Solution

To address this vulnerability, apply SAP Note 1659560 or import the necessary changes via the relevant support package. Note 1701662 is a prerequisite for this update.

References

Full note on SAP: SAP Support Launchpad note 1659560

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More