SAP security note 1679689, "ROS: Unauthorized modification in BSP application". Below are the symptom and SAP recommended solution.
Description
Symptom
The SRM-ROS application component is vulnerable to unauthorized modifications in BSP applications. Specifically, the ROS_SELF_REG and ROS_SELF_EDIT functions do not adequately encode OUTPUT parameters, leading to a Cross-Site Scripting (XSS) vulnerability. This flaw allows malicious users to alter displayed application content without proper authorization and potentially steal authentication information from legitimate users. If an attacker impersonates an administrator, the entire application’s security can be compromised.
Solution
To address this vulnerability, implement the relevant support packages or apply the provided correction instructions.
Full note on SAP: SAP Support Launchpad note 1679689
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
