Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

WebReportingUnauthorized modification of displayed content, SAP security note 1536640

SAP Note 1536640
High priority

SAP security note 1536640, "WebReporting: Unauthorized modification of displayed content", is a note released on May 10, 2011. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Please read SAP Note 524995 > WebRFC, WebReporting
PriorityCorrection with high priority
Released onMay 10, 2011

Description

Symptom

WebReporting can be abused by a malicious user, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.

Solution

Please apply the following patch: Download for SNOTE.

Reason and prerequisites

A reflected cross-site scripting (XSS) issue in WebReporting allows a malicious user to non-permanently deface or modify displayed content from a website. Additionally, this vulnerability can be exploited to steal another user’s authentication information, potentially enabling an attacker to impersonate the user and access information with the same rights, thereby compromising the security of the application.

CVSS

Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N

References

Full note on SAP: SAP Support Launchpad note 1536640

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More