SAP security note 1676010, "Unauthorized modification of stored content in PA-GE", was released on 20.12.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
A critical security vulnerability has been identified in the PA-GE component of SAP, specifically involving a stored cross-site scripting (XSS) issue within the HRMGE_REQUEST BSP application. This vulnerability allows attackers to:
- Modify application content without authorization.
- Persist the modified content, potentially embedding malicious scripts.
- Steal authentication information from other legitimate users, enabling impersonation and unauthorized access to sensitive data.
Exploitation of this vulnerability can lead to:
- Persistent unauthorized modification of displayed content.
- Automatic rendering of malicious content without targeting individual victims.
- Theft of authentication data, allowing attackers to impersonate users and gain access with the same privileges.
Solution
To mitigate this vulnerability, you should:
- Import the Support Package: apply the support package provided in SAP Note 1676010.
- Implement Correction Instructions: follow the attached correction instructions within your system.
Full note on SAP: SAP Support Launchpad note 1676010
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




