Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in BSP, SAP security note 1699418

SAP Note 1699418
SAP Security Note
High priority

SAP security note 1699418, "Unauthorized modification of displayed content in BSP", is a program error note released on 13.12.2012. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Business Server Pages (BC-BSP)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on13.12.2012
LanguageEnglish

Description

Symptom

BSP applications using the GRAPHICS extension can be exploited by attackers to modify displayed application content without authorization. This vulnerability may also allow attackers to obtain authentication information from other legitimate users.

Solution

Apply the SAP Security Note 1699418 using the provided assistance tools.

Reason and prerequisites

Pages or views utilizing GRAPHICS extensions within certain BSP applications do not adequately encode OUTPUT parameters, leading to a reflected XSS vulnerability. An attacker can exploit this to non-permanently deface or modify website content and potentially steal user authentication information. If an administrator’s credentials are compromised, the security of the entire application may be at risk.

Full note on SAP: SAP Support Launchpad note 1699418

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More