SAP Security Note
High priority
SAP security note 1617266, “Unauthorized modification of content in Interaction Center”, is a program error note released on December 13, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Some functions in the CRM Interaction Center that use the so-called BTF editor can be abused by a malicious user, allowing them to modify application content, persist the modified content without authorization, and potentially obtain authentication information from other legitimate users.
Solution
- Implement SAP Note 1577766 first.
- After implementing the attached correction instructions, content processed by the BTF editor will be filtered. If filtering is not possible, the content will be removed.
- For ERMS E-mail Workbench and the Agent Inbox E-Mail Editor, activate filtering explicitly:
- Execute a new parameter value for the parameter controlling the display of HTML mails.
- Refer to the manual steps for the corresponding release for detailed instructions.
Reason and prerequisites
Using certain functions in the CRM Interaction Center that utilize the BTF editor can result in a stored cross-site scripting issue. This vulnerability allows malicious users to permanently modify displayed content on a website, enabling them to embed content that is rendered automatically without needing to target victims individually. Additionally, stored cross-site scripting can be exploited to steal another user’s authentication information, such as data related to their current session. A malicious user who gains access to this data may impersonate the user and access all information with the same rights as the target user. If an administrator is impersonated, the security of the application may be fully compromised.
References
Full note on SAP: SAP Support Launchpad note 1617266
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
