SAP security note 1679963, "Unauthorized modification in BSP application in CRM-IC-EMS". Below are the symptom and SAP recommended solution.
Description
Symptom
Unauthorized modification of application content. Potential theft of user authentication information.
Solution
Apply SAP Security Note 1679963 or import the necessary changes via the relevant support package to address the cross-site scripting issue.
Reason and prerequisites
BSP Pages within CRM-IC-EMS do not adequately encode OUTPUT parameters, leading to a cross-site scripting (XSS) vulnerability. This flaw can be exploited to steal authentication data, allowing attackers to impersonate users and gain unauthorized access.
Full note on SAP: SAP Support Launchpad note 1679963
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




