Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in PA-GE, SAP security note 1676010

SAP Note 1676010

SAP security note 1676010, "Unauthorized modification of stored content in PA-GE", was released on 20.12.2012. Below are the symptom and SAP recommended solution.

ComponentPA-GE (Personnel Management > Global Employees)
Version5
StatusReleased for Customer
Released on20.12.2012

Description

Symptom

A critical security vulnerability has been identified in the PA-GE component of SAP, specifically involving a stored cross-site scripting (XSS) issue within the HRMGE_REQUEST BSP application. This vulnerability allows attackers to:

  • Modify application content without authorization.
  • Persist the modified content, potentially embedding malicious scripts.
  • Steal authentication information from other legitimate users, enabling impersonation and unauthorized access to sensitive data.

Exploitation of this vulnerability can lead to:

  • Persistent unauthorized modification of displayed content.
  • Automatic rendering of malicious content without targeting individual victims.
  • Theft of authentication data, allowing attackers to impersonate users and gain access with the same privileges.

Solution

To mitigate this vulnerability, you should:

  • Import the Support Package: apply the support package provided in SAP Note 1676010.
  • Implement Correction Instructions: follow the attached correction instructions within your system.

Full note on SAP: SAP Support Launchpad note 1676010

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More