SAP security note 1567604, "Unauthorized modification of displayed content in BSP", is released on July 12, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A BSP test application can be abused by a malicious user, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.
Solution
Use the latest SAP BASIS support package or implement the correction instructions manually.
Reason and prerequisites
HTTP pages within a BSP test application do not sufficiently encode the HTTP parameters, resulting in a reflected cross-site scripting issue. This vulnerability can be exploited to deface or modify displayed web content temporarily and to steal authentication information, potentially allowing impersonation of users, including administrators.
Full note on SAP: SAP Support Launchpad note 1567604
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
