SAP security note 1497165, "Unauthorized modification of displayed content in IC E-mail". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability exists in the Interaction Center (IC) E-mail application that allows malicious users to modify displayed application content without authorization. This can potentially lead to the theft of authentication information from other legitimate users, enabling attackers to impersonate users and gain unauthorized access to sensitive information. If an administrator’s credentials are compromised, the application’s security could be fully breached.
Solution
Apply the corresponding support package for your software component version.
Additionally, follow the correction instructions provided in the support package to ensure the vulnerability is fully addressed.
References
Affected components
- BBPCRM 520
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
Full note on SAP: SAP Support Launchpad note 1497165
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
