Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification in ITS-Service in IS-U-WA, SAP security note 1677810

SAP Note 1677810

SAP security note 1677810, "Unauthorized modification in ITS-Service in IS-U-WA". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Security Note 1677810 addresses a critical cross-site scripting (XSS) vulnerability in the ITS Service EWHV_WASTE within the IS-U-WA component. This vulnerability allows malicious users to modify displayed application content without authorization and potentially steal authentication information from legitimate users.

Solution

To mitigate this vulnerability, apply SAP Note 1677810 along with the prerequisite notes 1621946 and 1488500. Ensure that your IS-UT component is updated to the appropriate support package as specified in the note.

References

Affected components

  • IS-UT versions 600, 602, 603, 604, 605, 606, 616

Full note on SAP: SAP Support Launchpad note 1677810

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More