Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of BSP in Webdocuments, SAP security note 1676722

SAP Note 1676722
High priority

SAP security note 1676722, “Unauthorized modification of BSP in Webdocuments”, released on 08.05.2012. Below are the symptom, SAP recommended solution and the affected software components.

PriorityCorrection with high priority
StatusReleased for Customer
Released on08.05.2012

Description

Symptom

Malicious users can unauthorizedly modify Webdocuments content and potentially obtain authentication information from other users.

Solution

Apply SAP Security Note 1676722 or import the necessary changes via the relevant support packages.

Reason and prerequisites

The Webdynpro class DPWTY_CL_UI_CLAIM_DETAIL does not properly encode output parameters, leading to a cross-site scripting (XSS) vulnerability. This can be exploited to steal authentication data, impersonate users, and compromise overall application security, especially if administrative accounts are targeted.

References

Affected components

  • Industry-Specific Components > Automotive > Dealer Portal > Warranty Online WebFrontend (IS-A-DP-WTY)

Full note on SAP: SAP Support Launchpad note 1676722

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More