High priority
SAP security note 1665004, “Unauthorized modification of BSPs in CRM Grantor Management”, is a note released on May 8, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A critical security vulnerability has been identified in CRM Grantor Management (Component: CRM-IPS-BTX-APL) that allows unauthorized modification of BSP (Business Server Pages). This can lead to malicious users altering displayed application content without proper authorization and potentially accessing sensitive authentication information.
Solution
- Apply Prerequisite: Implement SAP Note 1701662 to address related vulnerabilities.
- Implement Correction: Follow the correction instructions provided in SAP Note 1665004 or import the necessary changes via the relevant support package.
Reason and prerequisites
Vulnerability Type: Cross-site scripting (XSS)
- Unauthorized modification of application content.
- Potential theft of user authentication information.
- Risk of impersonating users, including administrators, leading to full compromise of application security.
References
- SAP Note 1701662 – Unauthorized modification of display content in Web Request
- SAP Note 1582870 – ABAP XSS Escaping Support
- SAP Note 1582867 – Security options (XSS) for ESCAPE
Affected components
- CRM-IPS-BTX-APL versions 500, 520, 600, 700, 701, 702, 712
Full note on SAP: SAP Support Launchpad note 1665004
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
