Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modific. of displ.content in CRM_WR_DEMO03, SAP security note 1490868

SAP Note 1490868
SAP Security Note
High priority

SAP security note 1490868, “Unauthorized modification of display content in CRM_WR_DEMO03”, was released on 09.11.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Internet Service > Web Forms (CRM-ISE-WBF)
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on09.11.2010

Description

Symptom

The component CRM_WR_DEMO03 can be exploited by a malicious user to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.

Solution

Apply this SAP Note using the Note Assistant!

Important: for release SAP_BASIS 620 (CRM release 400), SAP Note 1475840 is a prerequisite for applying this note.

Reason and prerequisites

Pages within the component CRM_TBOX_UPLOAD do not sufficiently encode output parameters, leading to a reflected cross-site scripting vulnerability. This can allow attackers to deface or modify content displayed on the website or steal authentication information, enabling them to impersonate users and potentially compromise the application’s security entirely.

References

Affected components

  • SAP_BASIS: 620
  • BBPCRM: 400, 500, 510, 520, 600, 700, 701

Full note on SAP: SAP Support Launchpad note 1490868

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More