Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in SRM-EBP, SAP security note 1681906

SAP Note 1681906
SAP Security Note
High priority

SAP security note 1681906, "Unauthorized modification of displayed content in SRM-EBP", is a program error note released on 08.05.2012. Below are the symptom and SAP recommended solution.

ComponentSupplier Relationship Management > SRM > Bid Invitation (SRM-EBP-BID)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on08.05.2012
LanguageEnglish

Description

Symptom

SRM-EBP contains a vulnerability that allows an attacker to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users. This is due to insufficient encoding of OUTPUT parameters in the BSP applications (CFX, CFXML_TEST, CFX_RFC_UI, CFX_TEST_SL, CFX_TEXT, CFX_UI2) and SICF services (CF, CFS, FOLDER, TOPICS, XMB_300), leading to reflected cross-site scripting (XSS) issues. An attacker could exploit this to deface or modify web content or steal user authentication data, potentially compromising the entire application if an administrator is impersonated.

Solution

Apply the correction instructions provided in this note or install the related support package relevant to your SAP component version.

References

Full note on SAP: SAP Support Launchpad note 1681906

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More