SAP Security Note
High priority
SAP security note 1699074, “Unauthorized modification of stored content in CRM_IT_DEALER”. Below are the symptom and SAP recommended solution.
Description
Symptom
Application CRM_IT_DEALER can be abused by an attacker, allowing them to modify application content, persist the modified content without authorization, and potentially obtain authentication information from other legitimate users.
Solution
Delete the BSP Application CRM_IT_DEALER using transaction SE80. This application was never released for customer usage and can be safely removed.
Reason and prerequisites
The BSP Application CRM_IT_DEALER results in a stored cross-site scripting issue. It allows attackers to permanently modify displayed content from a website, embedding content that is rendered automatically without targeting victims individually. Additionally, stored XSS can be used to steal another user’s authentication information, enabling impersonation and access to all information with the same rights as the target user. If an administrator is impersonated, the application’s security may be fully compromised.
Full note on SAP: SAP Support Launchpad note 1699074
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
