SAP security note 1491867, "Unauthorized Modification of Displayed Broadcasting Content". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses an issue where the broadcasting component in SAP can be abused by a malicious user. An attacker could modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
A reflected cross-site scripting (XSS) attack can be utilized to non-permanently deface or modify displayed content on a web site. This vulnerability allows attackers to steal another user’s authentication information, such as data related to their current session. With this information, an attacker could impersonate the user and access all information and functionalities available to that user. If an administrator’s credentials are compromised, it could lead to a complete security breach of the application.
Solution
All customizing data are now escaped by the API, ensuring that malicious JavaScript code in the customizing table will not be executed. It is crucial to apply the attached correction instructions provided in the security note.
References
- Update #1 to Security Note 1491867 (SAP Note 1557996)
- SAP Note 1355094 – Logon Popup when navigating to Broadcast Messaging Supervisor
- SAP Note 1169768 – Broadcast Messaging F4 user lookup re-ordering & select
Affected components
- CRM-IC-BRO (Customer Relationship Management > Interaction Center WebClient > Broadcast Messaging)
- WEBCUIF
- SAP_ABA
- CRMUIF
- CRMIS
Full note on SAP: SAP Support Launchpad note 1491867
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




