SAP security note 1644756, "Unauthorized Modification in CRM IC – Stored XSS Vulnerability", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Some functions in the CRM Interaction Center that utilize the BTF editor can be exploited by a malicious user. This allows unauthorized modification of application content, persistence of the altered content without proper authorization, and potential access to authentication information of other legitimate users.
Solution
Implement the attached correction instructions to ensure that content processed by the BTF editor is properly filtered. If filtering is not feasible, the content will be removed to prevent unauthorized modifications.
Reason and prerequisites
Exploiting certain functions within the CRM Interaction Center’s BTF editor can lead to a stored cross-site scripting (XSS) vulnerability. This vulnerability enables attackers to:
- Permanently modify website content, embedding malicious content that executes automatically without targeting individual victims.
- Steal authentication information, such as session data, from other users.
- Impersonate users, including administrators, potentially compromising the entire application’s security.
Affected components
- BBPCRM Versions: 500, 520, 600, 700, 701, 702, 712
Full note on SAP: SAP Support Launchpad note 1644756
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



