Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in PT-RC-UI-XS, SAP security note 1683929

SAP Note 1683929

SAP security note 1683929, "Unauthorized Modification of Stored Content in PT-RC-UI-XS". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can:

  • Modify application content persistently without authorization.
  • Embed malicious content that is automatically rendered.
  • Steal authentication information, allowing impersonation of legitimate users, including administrators.

Solution

  • Import the relevant Support Package for your SAP release.
  • Implement the provided correction instructions available here.

Reason and prerequisites

The BSP applications ESS_LEAVEREQUEST_ADMIN and ESS_LEAVEREQUEST_APPROVER have a stored XSS vulnerability. This allows attackers to permanently alter displayed content on a website and steal authentication data.

References

Affected components

  • SAP_HRRXX (versions 470, 500, 600, 604)

Full note on SAP: SAP Support Launchpad note 1683929

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More