SAP Security Note
High priority
SAP security note 1497183, "Unauthorized Modification of Content in BSP_CIC_DASHBOARD", was released on April 26, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The BSP application BSP_CIC_DASHBOARD can be exploited by malicious users to modify displayed application content without authorization. This vulnerability may allow attackers to obtain authentication information from legitimate users.
Solution
The BSP application has been deprecated and the related code has been deleted, mitigating the security risk.
Reason and prerequisites
Insufficient encoding of input/output parameters in BSP_CIC_DASHBOARD pages leads to a reflected XSS vulnerability.
Affected components
- BBPCRM: Versions 400, 500, 520, 600, 700, 701
Full note on SAP: SAP Support Launchpad note 1497183
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
