High priority
SAP security note 1695324, "Unauthorized Modification of Displayed Content in CRM-IC-SCR", is a program error note released on 08.05.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can exploit the CRM-IC-SCR by modifying displayed content without authorization and potentially obtaining authentication information from legitimate users.
Solution
To mitigate this vulnerability, follow these steps to update the applet:
- Load the Updated Applet:
- Download the ISE50_JDK5.jar file from the attachment to your local system.
- Go to transaction SE80 in your SAP system.
- Select "BSP Application" from the Repository Browser dropdown and press Enter.
- Navigate to CRM_IC_ISE -> MIMEs -> editor.
- Right-click on the "editor" folder and select "Import MIME objects."
- Locate and select the downloaded ISE50_JDK5.jar file.
- Enter the name and description as ISE50_JDK5.jar.
- Save the changes.
- Clear Java Cache:
- Close all Internet Explorer windows.
- Go to the Control Panel -> Programs -> Java -> General Tab.
- Click on "Settings" under Temporary Internet Files and select "Delete Files."
After performing these steps, the ise.jsp file will be removed from the Interactive Scripting Applet, ensuring it is no longer accessible at \images\ise.jsp.
Reason and prerequisites
The API interface within CRM-IC-SCR does not sufficiently encode input parameters, leading to a reflected XSS vulnerability. This allows attackers to deface or modify website content temporarily and steal authentication data, enabling user impersonation and compromising application security.
CVSS
Score 0
Affected components
- CRMUIF 600
- WEBCUIF 700, 701, 730, 731, 746
Full note on SAP: SAP Support Launchpad note 1695324
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
