SAP security note 1754772, "Update 1 to security note 1744747". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Security note 1744747 has been rereleased with additional workarounds addressing stored cross-site scripting (XSS) vulnerabilities in the CRM-IPC and CRM-ISA-TEC components.
Solution
This update includes Java corrections for E-Commerce and Web Channel. To apply the fix:
- Apply the patch following the instructions in SAP Note 877887 for applying Java patches.
- Review the patch strategy described in SAP Note 1546959.
References
- 1744747 – Unauthorized modification of stored content in CRM-IPC
- 1546959 – Patch strategies for SAP E-Commerce solutions
- 877887 – Installing Patches for CRM Java Components and FSCM BD
Affected components
- SAP-CRMJAV (Versions 7.0, 7.01, 7.02, 7.30, 7.31, 7.32)
- SAP-CRMWEB
- SAP-SHRWEB
- SAP-SHRJAV
- SAP-CRMAPP
- SAP-SHRAPP
Full note on SAP: SAP Support Launchpad note 1754772
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




