SAP security note 1689843, "Unauthorized modification in component CRM-MKT-MPL-CA-BRE", is a program error note released on May 8, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can abuse the CRM-MKT-MPL-CA-BRE component to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
Solution
The BSP (Business Server Pages) is no longer being used and has been commented out in these releases. To address this issue, you should apply this security note or import the necessary changes via the relevant support package.
Reason and prerequisites
Several .htm files (including confirm.htm, create.htm, edit.htm, message.htm, overview.htm, text.htm, help.htm, start.htm, taglist.htm, and templsel.htm) within the CRM-MKT-MPL-CA-BRE component do not sufficiently encode OUTPUT parameters. This results in a cross-site scripting (XSS) vulnerability, allowing attackers to:
- Non-permanently deface or modify displayed content on the website.
- Steal user authentication information, such as session data.
- Impersonate users, potentially granting unauthorized access with the same rights as the targeted user. If an administrator is impersonated, the application's security may be fully compromised.
References
This note refers to
Referenced by
Full note on SAP: SAP Support Launchpad note 1689843
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




