High
SAP security note 1659560, "Unauthorized Modification of Displayed Content in CRM-ISE-WBF", is a note released on May 8, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
BSP applications of the component CRM-ISE-WBF can be exploited by malicious users to modify displayed application content without authorization. This vulnerability allows attackers to potentially obtain authentication information from legitimate users, leading to impersonation and unauthorized access to sensitive information. Specifically, the issue stems from insufficient encoding of output parameters, resulting in a Cross-Site Scripting (XSS) vulnerability.
Solution
To address this vulnerability, apply SAP Note 1659560 or import the necessary changes via the relevant support package. Note 1701662 is a prerequisite for this update.
References
- SAP Note 1701662 – Unauthorized modification of displayed content in Web Request
- SAP Note 1582870 – ABAP XSS Escaping Support
- SAP Note 1582867 – Security options (XSS) for ESCAPE
- SAP Note 963724 – Web request performance optimization
Full note on SAP: SAP Support Launchpad note 1659560
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
