SAP security note 1677486, "Unauthorized modification in ITS-Service in SCM-APO-CA-COP", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can exploit SCM-APO-CA-COP to modify application content without proper authorization and obtain authentication details from other users.
Solution
To mitigate this vulnerability, apply the manual correction instructions provided in this note or import the changes via the relevant support package. Additionally, ensure that the corrections from SAP Notes 1621946 and 1488500 are implemented, as they are prerequisites for the effectiveness of this fix.
Reason and prerequisites
ITS Service components (AMON, AMON_STATIST, CLPBID, CLPPROMCAL, CLPSDP) within SCM-APO-CA-COP do not sufficiently encode output parameters, resulting in a cross-site scripting (XSS) vulnerability.
References
- SAP Note 1621946 – ITS: updated XSS-escaping functions
- SAP Note 1488500 – ITS: automatically escape context fields in output
Full note on SAP: SAP Support Launchpad note 1677486
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




