SAP Security Note
High priority
SAP security note 1592264, “Unauthorized modification of stored content in BTF-Editor”, is released on December 13, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The BTF-Editor is vulnerable to abuse by malicious users, allowing unauthorized modification of application content. This can lead to the persistence of malicious content and potential theft of authentication information from legitimate users through stored cross-site scripting (XSS) attacks. If exploited, attackers can impersonate users, including administrators, potentially compromising the entire application’s security.
Solution
To mitigate this vulnerability, apply the necessary corrections as outlined in this note. The solution involves implementing filter enhancements in the BTF-Editor to sanitize input and prevent malicious content from being stored and executed.
- A kernel with version 6.40 or higher must be installed. The filter functionality will not work with kernel version 6.20.
- Import the correction instructions contained in Note 1628569. This step is crucial and must be completed before performing the manual activities.
References
Affected components
- SAP_BASIS (620 to 731)
Full note on SAP: SAP Support Launchpad note 1592264
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
