Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of BSPs in CRM Grantor Management, SAP security note 1665004

SAP Note 1665004
High priority

SAP security note 1665004, “Unauthorized modification of BSPs in CRM Grantor Management”, is a note released on May 8, 2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCRM-IPS-BTX-APL
PriorityCorrection with high priority
StatusReleased for Customer
Released onMay 8, 2012

Description

Symptom

A critical security vulnerability has been identified in CRM Grantor Management (Component: CRM-IPS-BTX-APL) that allows unauthorized modification of BSP (Business Server Pages). This can lead to malicious users altering displayed application content without proper authorization and potentially accessing sensitive authentication information.

Solution

  • Apply Prerequisite: Implement SAP Note 1701662 to address related vulnerabilities.
  • Implement Correction: Follow the correction instructions provided in SAP Note 1665004 or import the necessary changes via the relevant support package.

Reason and prerequisites

Vulnerability Type: Cross-site scripting (XSS)

  • Unauthorized modification of application content.
  • Potential theft of user authentication information.
  • Risk of impersonating users, including administrators, leading to full compromise of application security.

References

Affected components

  • CRM-IPS-BTX-APL versions 500, 520, 600, 700, 701, 702, 712

Full note on SAP: SAP Support Launchpad note 1665004

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More