Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification in BSP in CA-GTF-IC-BRO, SAP security note 1676211

SAP Note 1676211SAP Security NoteHigh priority

SAP security note 1676211, “Unauthorized modification in BSP in CA-GTF-IC-BRO”, released on May 8, 2012. Below are the symptom and SAP recommended solution.

ComponentCross-Application Components > General Application Functions > use CRM-IC (Interaction Center WebClient) > use CRM-IC-BRO (Broadcast Messaging)
PriorityHigh priority
TypeSAP Security Note
StatusReleased for Customer
Released onMay 8, 2012
LanguageEnglish

Description

Symptom

A malicious user can abuse CA-GTF-IC-BRO to modify displayed application content without authorization. This could allow unauthorized access to authentication information of other legitimate users.

Solution

Apply SAP Note 1676211 or import the changes via the relevant support package.

Reason and prerequisites

BSP Pages within CA-GTF-IC-BRO do not sufficiently encode OUTPUT parameters, leading to a cross-site scripting vulnerability. This vulnerability can be exploited to steal users' authentication information, enabling attackers to impersonate users and potentially compromise the entire application's security.

Affected BSP Pages:

  • CRM_BM_COCKPIT.HTM
  • CRM_BM_DEFAULT.HTM
  • CRM_BM_ERROR_VIEW.HTM
  • CRM_BM_USERLIST.HTM

References

Full note on SAP: SAP Support Launchpad note 1676211

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More