High
SAP security note 1601535, “Displaying doc. contents that were changed w/o authorization”, is a program error note released on December 13, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Documents within the BC-SRV-COM environment can be exploited by attackers to:
- Modify application content without authorization.
- Persist the modified content.
- Steal authentication information from legitimate users, enabling impersonation and unauthorized access.
Solution
Implement the fixes using the Note Assistant or by importing the relevant Support Package available for your SAP_BASIS version.
After applying the correction, activate the HTML document filter to enhance security:
- For Release 7.31 and higher: the filter is enabled by default.
- For Release 7.30 and lower: manually activate the filter by setting the HTML_FILTER_FOR_DISPLAY parameter to ON in table SXPARAMS.
This filter removes potentially harmful content from HTML documents displayed in the Business Workplace, transactions SOST and SOIN.
Affected components
- SAP_BASIS (620 to 731)
Full note on SAP: SAP Support Launchpad note 1601535
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
