Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification in BSP application in CRM-IC-CHA, SAP security note 1674849

SAP Note 1674849

SAP security note 1674849, "Unauthorized modification in BSP application in CRM-IC-CHA", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

  • Unauthorized modification of application content.
  • Potential theft of authentication information through cross-site scripting (XSS).

Solution

Apply this SAP Note or import the changes via the relevant support package to address the vulnerability.

Reason and prerequisites

  • BSP Pages (SESSION_BUFFERED_FRAME.HTM, SPELLCHECKER.HTM) within CRM-IC-CHA do not sufficiently encode output parameters.
  • This insufficient encoding results in a cross-site scripting vulnerability.
  • An attacker can exploit this to steal session data and impersonate users, potentially compromising administrative accounts.

References

Full note on SAP: SAP Support Launchpad note 1674849

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More