Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Displaying doc. contents that were changed w/o authorization, SAP security note 1601535

SAP Note 1601535
High

SAP security note 1601535, “Displaying doc. contents that were changed w/o authorization”, is a program error note released on December 13, 2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Basis Services/Communication Interfaces > Communication Services: Mail, Fax, SMS, Telephony (BC-SRV-COM)
CategoryProgram error
PriorityHigh
StatusReleased for Customer
Released onDecember 13, 2011

Description

Symptom

Documents within the BC-SRV-COM environment can be exploited by attackers to:

  • Modify application content without authorization.
  • Persist the modified content.
  • Steal authentication information from legitimate users, enabling impersonation and unauthorized access.

Solution

Implement the fixes using the Note Assistant or by importing the relevant Support Package available for your SAP_BASIS version.

After applying the correction, activate the HTML document filter to enhance security:

  • For Release 7.31 and higher: the filter is enabled by default.
  • For Release 7.30 and lower: manually activate the filter by setting the HTML_FILTER_FOR_DISPLAY parameter to ON in table SXPARAMS.

This filter removes potentially harmful content from HTML documents displayed in the Business Workplace, transactions SOST and SOIN.

Affected components

  • SAP_BASIS (620 to 731)

Full note on SAP: SAP Support Launchpad note 1601535

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More