SAP Security Note
High priority
SAP security note 1699418, "Unauthorized modification of displayed content in BSP", is a program error note released on 13.12.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
BSP applications using the GRAPHICS extension can be exploited by attackers to modify displayed application content without authorization. This vulnerability may also allow attackers to obtain authentication information from other legitimate users.
Solution
Apply the SAP Security Note 1699418 using the provided assistance tools.
Reason and prerequisites
Pages or views utilizing GRAPHICS extensions within certain BSP applications do not adequately encode OUTPUT parameters, leading to a reflected XSS vulnerability. An attacker can exploit this to non-permanently deface or modify website content and potentially steal user authentication information. If an administrator’s credentials are compromised, the security of the entire application may be at risk.
Full note on SAP: SAP Support Launchpad note 1699418
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
