SAP Security Note
High priority
SAP security note 1665704, “Unauthorized modification of BSP in CRM-MD-BP-CCP”, is a program error note released on 08.05.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
The Application Component CRM-MD-BP-CCP can be exploited by a malicious user to modify displayed application content without authorization. Additionally, there is potential for unauthorized access to authentication information from legitimate users.
Solution
Apply this SAP Note or import the necessary changes via the relevant support package.
Reason and prerequisites
BSP Pages view_filter_test.xsl, default_mob.xsl, and default.xsl within the Application Component CRM-MD-BP-CCP do not adequately encode OUTPUT parameters. This deficiency leads to a cross-site scripting vulnerability.
Cross-site scripting can be leveraged to steal another user’s authentication information, such as session-related data. A malicious user who obtains this information can impersonate the user and access all information with the same permissions. If an administrator is impersonated, the entire application’s security may be compromised.
Full note on SAP: SAP Support Launchpad note 1665704
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




