High priority
SAP security note 1688660, “Unauthorized modification of stored content in BI_CONT”, is a program error note released on 08.05.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 1688660 addresses a critical vulnerability in the BI_CONT component. An attacker can exploit the class CL_RSBCT_XSA_FILE_PREVIEW to perform stored cross-site scripting (XSS) attacks. This vulnerability allows unauthorized modification of application content, persistence of the modified content, and potential theft of authentication information from legitimate users. If exploited, an attacker could impersonate users, including administrators, potentially compromising the entire application security.
- Unauthorized modification of stored content in BI_CONT.
- Potential theft of authentication information through stored XSS.
Solution
To mitigate this vulnerability, apply the correction instructions provided with SAP Note 1688660.
Affected components
- BI_CONT (versions 705, 706, 707, 724, 735, 737, 746, 747)
- Enterprise Performance Management > Spend Analytics (EPM-SA)
Full note on SAP: SAP Support Launchpad note 1688660
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
