High priority
SAP security note 1632687, "Unauthorized modification in BSP in CA-GTF-IC-SCR 2", is a program error note released on May 8, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit CA-GTF-IC-SCR to modify displayed application content without proper authorization. This can lead to the theft of authentication information from other legitimate users, allowing the attacker to impersonate users and gain unauthorized access to sensitive information.
Solution
To mitigate this vulnerability, apply SAP Note 1632687 or import the relevant support package. This note is part of a series of updates that should be applied in the following order for CRM 7.0 EHP2:
- 1. SAP Note 1687426 – Unauthorized modification in BSP in CA-GTF-IC-SCR 1
- 2. SAP Note 1632687 – Unauthorized modification in BSP in CA-GTF-IC-SCR 2
- 3. SAP Note 1687477 – Unauthorized modification in BSP in CA-GTF-IC-SCR 3
For releases below EHP2 of CRM 7.0, applying SAP Note 1687426 alone is sufficient as it contains all relevant changes.
References
- SAP Note 1687426 – Unauthorized modification in BSP in CA-GTF-IC-SCR 1
- SAP Note 1687477 – Unauthorized modification in BSP in CA-GTF-IC-SCR 3
Affected components
- CA-GTF-IC-SCR
Full note on SAP: SAP Support Launchpad note 1632687
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
