Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in CRM-ISA, SAP security note 1601155

SAP Note 1601155
SAP Security Note

SAP security note 1601155, "Unauthorized modification of displayed content in CRM-ISA", was released on 11.10.2011. Below are the symptom, the SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Internet Sales > Shop Management
TypeSAP Security Note
Version1
Released on11.10.2011

Description

Symptom

The Web Channel E-Commerce Shop Management (ShopAdmin) application is vulnerable to abuse by authenticated malicious users. This vulnerability allows unauthorized modification of displayed application content and may enable the theft of authentication information from other legitimate users through reflected cross-site scripting (XSS).

Solution

This security note provides Java corrections for the E-Commerce and Web Channel components to address the XSS vulnerability.

Apply the relevant Support Package Patch. Follow the instructions in SAP Note 877887 for applying Java patches. Refer to SAP Note 1546959 for detailed patch strategies.

Reason and prerequisites

The vulnerability arises because the ShopAdmin component does not sufficiently encode OUTPUT parameters. This insufficient encoding leads to a reflected XSS issue, which can be exploited to:

  • Non-permanently deface or modify website content.
  • Steal users’ authentication data, such as session information.
  • Impersonate users, potentially compromising application security entirely if an administrator is targeted.

CVSS

Score 0

References

Affected components

  • SAP-SHRWEB
  • SAP-CRMWEB
  • SAP-CRMJAV
  • SAP-CRMAPP
  • SAP-SHRAPP

Full note on SAP: SAP Support Launchpad note 1601155

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.