SAP security note 1676211, “Unauthorized modification in BSP in CA-GTF-IC-BRO”, released on May 8, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can abuse CA-GTF-IC-BRO to modify displayed application content without authorization. This could allow unauthorized access to authentication information of other legitimate users.
Solution
Apply SAP Note 1676211 or import the changes via the relevant support package.
Reason and prerequisites
BSP Pages within CA-GTF-IC-BRO do not sufficiently encode OUTPUT parameters, leading to a cross-site scripting vulnerability. This vulnerability can be exploited to steal users' authentication information, enabling attackers to impersonate users and potentially compromise the entire application's security.
Affected BSP Pages:
- CRM_BM_COCKPIT.HTM
- CRM_BM_DEFAULT.HTM
- CRM_BM_ERROR_VIEW.HTM
- CRM_BM_USERLIST.HTM
References
- 1671470 – BSP: Design2008 for release 7.00 and 7.01
- 1582870 – ABAP XSS Escaping Support
- 1582867 – Security options (XSS) for ESCAPE
Full note on SAP: SAP Support Launchpad note 1676211
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
