Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of content in Interaction Center, SAP security note 1617266

SAP Note 1617266
SAP Security Note
High priority

SAP security note 1617266, “Unauthorized modification of content in Interaction Center”, is a program error note released on December 13, 2011. Below are the symptom and SAP recommended solution.

ComponentCustomer Relationship Management > Interaction Center WebClient > E-Mail Response Management System
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released onDecember 13, 2011

Description

Symptom

Some functions in the CRM Interaction Center that use the so-called BTF editor can be abused by a malicious user, allowing them to modify application content, persist the modified content without authorization, and potentially obtain authentication information from other legitimate users.

Solution

  • Implement SAP Note 1577766 first.
  • After implementing the attached correction instructions, content processed by the BTF editor will be filtered. If filtering is not possible, the content will be removed.
  • For ERMS E-mail Workbench and the Agent Inbox E-Mail Editor, activate filtering explicitly:
    • Execute a new parameter value for the parameter controlling the display of HTML mails.
    • Refer to the manual steps for the corresponding release for detailed instructions.

Reason and prerequisites

Using certain functions in the CRM Interaction Center that utilize the BTF editor can result in a stored cross-site scripting issue. This vulnerability allows malicious users to permanently modify displayed content on a website, enabling them to embed content that is rendered automatically without needing to target victims individually. Additionally, stored cross-site scripting can be exploited to steal another user’s authentication information, such as data related to their current session. A malicious user who gains access to this data may impersonate the user and access all information with the same rights as the target user. If an administrator is impersonated, the security of the application may be fully compromised.

References

Full note on SAP: SAP Support Launchpad note 1617266

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More