High priority
SAP security note 1589716, "Unauthorized modification of displayed content in the Portal", is a faq note released on November 8, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A reflected Cross Site Scripting (XSS) vulnerability exists within the Portal runtime. This allows attackers to:
- Non-permanently deface or modify displayed content on the website.
- Steal another user’s authentication information, potentially leading to impersonation and unauthorized access.
- If an administrator is impersonated, it may result in a full compromise of the application’s security.
Solution
To address this security issue, apply the appropriate Support Package (SP) Patch Level. You can find the relevant patches under the “SP Patch Level” tab in this security note.
Reason and prerequisites
The issue arises because the Portal runtime does not sufficiently encode input parameters, resulting in a reflected XSS vulnerability. This allows attackers to:
- Modify displayed content without authorization.
- Steal authentication data from legitimate users.
- Potentially impersonate users with the same access rights, including administrators, leading to significant security breaches.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
Full note on SAP: SAP Support Launchpad note 1589716
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




