SAP security note 1672569, “Unauthorized modification of stored content in CRM-ISA”. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can exploit CRM-ISA to modify application content without authorization, persist these changes, and potentially steal authentication information from other legitimate users.
Stored Cross-Site Scripting (XSS): Allows attackers to embed malicious content that executes automatically when users access the affected web application. Authentication Information Theft: Attackers can steal users’ authentication data, enabling them to impersonate users, including administrators, which can lead to a full compromise of the application’s security.
Solution
Apply the support package patch attached to this SAP Note. For detailed instructions on applying Java patches, refer to SAP Note 877887. Additionally, consult SAP Note 1546959 for information on the patching strategy.
References
- SAP Note 1546959 – Patch strategies for SAP E-Commerce solutions
- SAP Note 877887 – Installing Patches for CRM Java Components and FSCM BD
Full note on SAP: SAP Support Launchpad note 1672569
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
