SAP security note 1675734, “Unauthorized modification in ITS-Services in BBP”, is a program error note released on 08.05.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can modify application content and steal authentication information, potentially impersonating users, including administrators, leading to compromised application security.
Solution
Apply this note or import the changes via the relevant support package. Ensure that corrections from SAP Note 1621946 and SAP Note 1488500 are also implemented to ensure full protection.
Execute the report RITS_XSS_PARAM_FORM_OCIAGENT included in the correction instructions and provide the transport request number when prompted. This report will add service parameters for the adapted ITS services.
Reason and prerequisites
ITS Services BBP_FREEFORM and BBP_OCI_AGENT within SRM-EBP-PRC do not sufficiently encode OUTPUT parameters, resulting in a cross-site scripting (XSS) vulnerability. This can be exploited to steal authentication information and impersonate users.
Full note on SAP: SAP Support Launchpad note 1675734
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




