Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of content in transaction launcher, SAP security note 1674616

SAP Note 1674616
SAP Security Note
High priority

SAP security note 1674616, “Unauthorized modification of content in transaction launcher”, is a program error note released on July 5, 2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCross-Application Components > WebClient User Interface > Application Frame
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onJuly 5, 2012
LanguageEnglish

Description

Symptom

When the CRM Transaction Launcher is used to launch backend applications, a malicious user can:

  • Modify application content
  • Persist the modified content without authorization
  • Potentially obtain authentication information from other legitimate users

This vulnerability allows for unauthorized actions such as embedding malicious content or stealing user authentication data.

Solution

Implement the correction instructions provided in the note to address the vulnerability.

Reason and prerequisites

Applications utilizing the CRM Transaction Launcher are vulnerable to stored XSS attacks. This allows for the permanent modification of displayed content on a website, enabling malicious users to embed content that is automatically rendered without needing to target individual victims. Additionally, attackers can steal authentication information, leading to user impersonation and potential full compromise of the application’s security.

Affected components

  • SAP_ABA: 700
  • CRMUIF: 600
  • PI: 2004_1_470 to 2004_1_500
  • WEBCUIF: 700, 701, 730, 731, 746

Full note on SAP: SAP Support Launchpad note 1674616

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More