SAP Security Note
SAP security note 1601155, "Unauthorized modification of displayed content in CRM-ISA", was released on 11.10.2011. Below are the symptom, the SAP recommended solution and the affected software components.
Description
Symptom
The Web Channel E-Commerce Shop Management (ShopAdmin) application is vulnerable to abuse by authenticated malicious users. This vulnerability allows unauthorized modification of displayed application content and may enable the theft of authentication information from other legitimate users through reflected cross-site scripting (XSS).
Solution
This security note provides Java corrections for the E-Commerce and Web Channel components to address the XSS vulnerability.
Apply the relevant Support Package Patch. Follow the instructions in SAP Note 877887 for applying Java patches. Refer to SAP Note 1546959 for detailed patch strategies.
Reason and prerequisites
The vulnerability arises because the ShopAdmin component does not sufficiently encode OUTPUT parameters. This insufficient encoding leads to a reflected XSS issue, which can be exploited to:
- Non-permanently deface or modify website content.
- Steal users’ authentication data, such as session information.
- Impersonate users, potentially compromising application security entirely if an administrator is targeted.
CVSS
Score 0
References
- Unauthorized modification of displayed content in ISA-AUC (1603081)
- Unauthorized modification of displayed content in ISA B2B (1583300)
- Patch strategies for SAP E-Commerce solutions (1546959)
- Unauthorized modification of displayed content (1509342)
- Installing Patches for CRM Java Components and FSCM BD (877887)
Affected components
- SAP-SHRWEB
- SAP-CRMWEB
- SAP-CRMJAV
- SAP-CRMAPP
- SAP-SHRAPP
Full note on SAP: SAP Support Launchpad note 1601155
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




