SAP Security Note
High priority
SAP security note 1484711, "Unauthorized change of displayed contents in IUBOTRCP", is a program error note released on 10.08.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
By manipulating IUBOTRCP or IUOVA, an attacker can change displayed data of another user without authorization and may also be able to access his authorization data.
Solution
Implement the corrections.
Reason and prerequisites
Reflected cross-site scripting can be triggered due to inadequate output coding. As a result, the content of a Web page can be manipulated when a manipulated link is called, for example.
An attacker can use reflected cross-site scripting to steal the logon information of the current session of a victim. The attacker can then use this information to pretend to the server that he is the victim and can use the application with the same rights as the user who was attacked.
If the target of the attack is a user with administrative rights, all of the application data may be compromised as a result.
Full note on SAP: SAP Support Launchpad note 1484711
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
