SAP security note 1679401, "Unauthorized modification in BSP application CRM-MKT-MPL-CA". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can modify displayed application content without authorization and potentially steal authentication information, leading to user impersonation and compromised application security.
Solution
Apply SAP Note 1679401 or import the changes via the relevant support package.
Reason and prerequisites
Certain HTML files within the CRM-MKT-MPL-CA component do not sufficiently encode output parameters, resulting in a cross-site scripting issue.
Affected components
- CRM-MKT-MPL-CA
Full note on SAP: SAP Support Launchpad note 1679401
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
