SAP security note 1485271, “Unauthorized modification of stored content in CRM_1O_TDOCU”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can abuse the CRM_1O_TDOCU component to:
- Modify application content and persist these changes without authorization.
- Embed malicious content that is rendered automatically, facilitating widespread exploitation.
- Steal authentication information such as session data, enabling user impersonation and unauthorized access.
Solution
Apply the corresponding support package or follow the manual instructions provided in the security note.
Reason and prerequisites
The vulnerability arises from the CRM_1O_TDOCU component, leading to a stored cross site scripting issue. This allows for permanent modification of displayed content and potential theft of user authentication data. Administrators impersonated through this vulnerability can result in complete security compromise of the application.
Full note on SAP: SAP Support Launchpad note 1485271
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



