Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in CRM-IC-SCR, SAP security note 1695324

SAP Note 1695324
High priority

SAP security note 1695324, "Unauthorized Modification of Displayed Content in CRM-IC-SCR", is a program error note released on 08.05.2012. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityCorrection with high priority
StatusReleased for Customer
Released on08.05.2012

Description

Symptom

An attacker can exploit the CRM-IC-SCR by modifying displayed content without authorization and potentially obtaining authentication information from legitimate users.

Solution

To mitigate this vulnerability, follow these steps to update the applet:

  • Load the Updated Applet:
    • Download the ISE50_JDK5.jar file from the attachment to your local system.
    • Go to transaction SE80 in your SAP system.
    • Select "BSP Application" from the Repository Browser dropdown and press Enter.
    • Navigate to CRM_IC_ISE -> MIMEs -> editor.
    • Right-click on the "editor" folder and select "Import MIME objects."
    • Locate and select the downloaded ISE50_JDK5.jar file.
    • Enter the name and description as ISE50_JDK5.jar.
    • Save the changes.
  • Clear Java Cache:
    • Close all Internet Explorer windows.
    • Go to the Control Panel -> Programs -> Java -> General Tab.
    • Click on "Settings" under Temporary Internet Files and select "Delete Files."

After performing these steps, the ise.jsp file will be removed from the Interactive Scripting Applet, ensuring it is no longer accessible at \images\ise.jsp.

Reason and prerequisites

The API interface within CRM-IC-SCR does not sufficiently encode input parameters, leading to a reflected XSS vulnerability. This allows attackers to deface or modify website content temporarily and steal authentication data, enabling user impersonation and compromising application security.

CVSS

Score 0

Affected components

  • CRMUIF 600
  • WEBCUIF 700, 701, 730, 731, 746

Full note on SAP: SAP Support Launchpad note 1695324

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More