SAP security note 1572325, "Unauthorized modification of displayed content in BW", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
A legacy BW service can be abused by a malicious user, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.
Solution
- SAP NetWeaver BW 7.00: Import Support Package 27 for SAP NetWeaver BW 7.00 (SAPKW70027) into your BW system. The Support Package will be available as soon as note 1567706 with the short text "SAPBWNews NW BW 7.0 ABAP SP27", which describes this Support Package in more detail, is released for customers.
- SAP NetWeaver BW 7.01 (SAP NW BW7.0 EnhP 1): Import Support Package 10 for SAP NetWeaver BW 7.01 (SAPKW70110) into your BW system. The Support Package will be available as soon as note 1419539 with the short text "SAPBINews NW7.01 BW ABAP SP10", which describes this Support Package in more detail, is released for customers.
- SAP NetWeaver BW 7.02 (SAP NW BW7.0 EnhP 2): Import Support Package 09 for SAP NetWeaver BW 7.02 (SAPKW70209) into your BW system. The Support Package will be available as soon as note 1581161 with the short text "Preliminary Version SAPBWNews NW BW 7.02 ABAP SP09", which describes this Support Package in more detail, is released for customers.
- SAP NetWeaver BW 7.11: Import Support Package 08 for SAP NetWeaver BW 7.11 (SAPKW71108) into your BW system. The Support Package will be available as soon as SAP note 1510977 with the short text "Preliminary Version SAPBINews NW7.11 BW ABAP SP8", which describes this Support Package in more detail, is released for customers.
- SAP NetWeaver BW 7.30: Import Support Package 04 for SAP NetWeaver BW 7.30 (SAPKW73004) into your BW system. The Support Package will be available as soon as note 1583516 with the short text "SAPBWNews NW7.30 BW ABAP SP04", which describes this Support Package in more detail, is released for customers.
In urgent cases, you can use the correction instructions. Beforehand, definitely check SAP Note 875986 for transaction SNOTE. This note might already be available before the Support Package is released. In this case, however, the short text still contains the terms "preliminary version".
Reason and prerequisites
Services within BW do not sufficiently encode OUTPUT parameters, resulting in a reflected cross-site scripting issue. A reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content from a website. Reflected cross-site scripting can be used to steal another user’s authentication information, such as data relating to their current session. A malicious user who gains access to this data may use it to impersonate the user and access all information with the same rights as the target user. If an administrator is impersonated, the security of the application may be fully compromised.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
References
Full note on SAP: SAP Support Launchpad note 1572325
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




