SAP security note 1743377, "Unauthorized modification of displayed content in EP-PSERV", is a program error note released on 11.12.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Appdesigner can be abused by an attacker, allowing them to modify displayed application content without authorization, and potentially obtain authentication information from other legitimate users.
Solution
Check the appropriate Support Package Patch level under the “SP Patchlevel” tab in this note to address the issue.
CVSS
Score 4.9 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:N
References
- Central Note for Portal Platform in SAP NW7.0 EhP2 SP13
- Central Note for Portal Platform in SAP NW7.0 EhP1 SP13
- Central Note for Portal Platform in SAP NetWeaver 04 SP31
- Central Note for Portal Platform in SAP NW7.0 SP28
Affected components
- EP-PSERV 7.00 to 7.02
- EP-PSERV 6.0_640
Full note on SAP: SAP Support Launchpad note 1743377
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



