Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in CRM_IT_DEALER, SAP security note 1699074

SAP Note 1699074
SAP Security Note
High priority

SAP security note 1699074, “Unauthorized modification of stored content in CRM_IT_DEALER”. Below are the symptom and SAP recommended solution.

ComponentCRM-BTX-PRV
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer

Description

Symptom

Application CRM_IT_DEALER can be abused by an attacker, allowing them to modify application content, persist the modified content without authorization, and potentially obtain authentication information from other legitimate users.

Solution

Delete the BSP Application CRM_IT_DEALER using transaction SE80. This application was never released for customer usage and can be safely removed.

Reason and prerequisites

The BSP Application CRM_IT_DEALER results in a stored cross-site scripting issue. It allows attackers to permanently modify displayed content from a website, embedding content that is rendered automatically without targeting victims individually. Additionally, stored XSS can be used to steal another user’s authentication information, enabling impersonation and access to all information with the same rights as the target user. If an administrator is impersonated, the application’s security may be fully compromised.

Full note on SAP: SAP Support Launchpad note 1699074

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More