Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorizd modification in ITS services, SAP security note 1674713

SAP Note 1674713
SAP Security Note
High priority

SAP security note 1674713, "Unauthorized modification in ITS services", was released on 08.05.2012. Below are the symptom and SAP recommended solution.

ComponentSupplier Relationship Management > SRM > Bid Invitation (SRM-EBP-BID)
PriorityHigh priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on08.05.2012

Description

Symptom

The SRM-EBP-BID component can be exploited by a malicious user to modify displayed application content without authorization. This vulnerability may allow the theft of authentication information from other legitimate users.

Solution

Apply this SAP Security Note or import the changes via the relevant support package. Additionally, ensure that the corrections from SAP Notes 1621946 and 1488500 are implemented to fully mitigate the vulnerability.

Reason and prerequisites

ITS Services [BBPAT04, BBPATTRMAINT, BBPADM_COCKPIT, BBPWEBMONITOR, BBPWEBMON_SEP, BBP_CTR_MON, BBPHELP, BBPOR01, BBPOR02, BBPPS01, and PSSRM_TNDR (only in SRM 7.02)] within SRM-EBP-BID do not sufficiently encode OUTPUT parameters, resulting in a cross-site scripting (XSS) issue. This vulnerability can be exploited to steal a user’s authentication information, allowing an attacker to impersonate the user and access data with the same privileges.

If an administrator is impersonated, the security of the entire application may be fully compromised.

References

Full note on SAP: SAP Support Launchpad note 1674713

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More