SAP Security Note
High priority
SAP security note 1490868, “Unauthorized modification of display content in CRM_WR_DEMO03”, was released on 09.11.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The component CRM_WR_DEMO03 can be exploited by a malicious user to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
Solution
Apply this SAP Note using the Note Assistant!
Important: for release SAP_BASIS 620 (CRM release 400), SAP Note 1475840 is a prerequisite for applying this note.
Reason and prerequisites
Pages within the component CRM_TBOX_UPLOAD do not sufficiently encode output parameters, leading to a reflected cross-site scripting vulnerability. This can allow attackers to deface or modify content displayed on the website or steal authentication information, enabling them to impersonate users and potentially compromise the application’s security entirely.
References
Affected components
- SAP_BASIS: 620
- BBPCRM: 400, 500, 510, 520, 600, 700, 701
Full note on SAP: SAP Support Launchpad note 1490868
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




