Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification in ITS-Service in IS-ADEC-BOQ., SAP security note 1673131

SAP Note 1673131

SAP security note 1673131, "Unauthorized modification in ITS-Service in IS-ADEC-BOQ", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The application component IS-ADEC-BOQ can be exploited by a malicious user to modify displayed application content without authorization. Additionally, it may allow unauthorized access to authentication information of other legitimate users.

Solution

  1. Apply the security note: use the SNOTE transaction to apply this note.
  2. Implement prerequisite notes: this note’s effectiveness depends on the implementation of SAP Note 1621946 and SAP Note 1488500.
  3. Execute correction instructions: after applying the note via SNOTE, run the ABAP program RITS_XSS_PARAM_BOS02 using transaction SE38 or SA38. Provide a transport request when prompted and use it to move the changes across the system landscape.

Reason and prerequisites

Within IS-ADEC-BOQ, the ITS Services BOS02 and BOS02_WAP do not sufficiently encode OUTPUT parameters, leading to a cross-site scripting vulnerability. This vulnerability can be exploited to steal authentication information, potentially allowing an attacker to impersonate users, including administrators, thereby compromising the application’s security.

Affected components

  • ECC-DIMP 500
  • ECC-DIMP 600
  • ECC-DIMP 602
  • ECC-DIMP 603
  • ECC-DIMP 604
  • ECC-DIMP 605
  • ECC-DIMP 606

Full note on SAP: SAP Support Launchpad note 1673131

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More