SAP security note 1675350, "Unauthorized modification in BSP appl. in CRM-ANA-MKT-CLV." Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can exploit CRM-ANA-MKT-CLV to:
- Modify displayed application content without proper authorization.
- Steal authentication information from legitimate users.
Solution
Apply SAP Security Note 1675350 or import the changes via the relevant support package. After applying the correction, the affected BSP Pages will be deactivated.
Reason and prerequisites
BSP Pages (RSAN_CLV_BSP, CLTV) within CRM-ANA-MKT-CLV do not sufficiently encode OUTPUT parameters, resulting in a Cross-Site Scripting (XSS) vulnerability.
- Stealing Authentication Information: Attackers can obtain session data, allowing them to impersonate users.
- User Impersonation: Unauthorized access to user accounts, potentially with the same privileges.
- Full Security Compromise: If an administrator’s account is compromised, the entire application security can be breached.
References
Full note on SAP: SAP Support Launchpad note 1675350
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
