SAP Security Note
High priority
SAP security note 1675411, "Unauthorized modification in BSP in CRM-IC-SCR", is a program error note released on May 8, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
- Unauthorized modification of application content
- Potential theft of authentication information via Cross-site Scripting (XSS)
Solution
Apply this security note or import the changes via the relevant support package associated with your system’s software components.
Reason and prerequisites
BSP Pages within CRM-IC-SCR do not sufficiently encode OUTPUT parameters, resulting in a cross-site scripting issue. Affected files include:
- CRMCMP_SCR SCRLEAD.HTM
- CRMCMP_SCR SCRTRANSCRIPT.HTM
- CRMCMP_SCR SCRURL.HTM
Affected components
- SAP_ABA 700
- BBPCRM 500
- BBPCRM 520
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
- BBPCRM 702
- BBPCRM 712
Full note on SAP: SAP Support Launchpad note 1675411
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
