SAP security note 1673131, "Unauthorized modification in ITS-Service in IS-ADEC-BOQ", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The application component IS-ADEC-BOQ can be exploited by a malicious user to modify displayed application content without authorization. Additionally, it may allow unauthorized access to authentication information of other legitimate users.
Solution
- Apply the security note: use the SNOTE transaction to apply this note.
- Implement prerequisite notes: this note’s effectiveness depends on the implementation of SAP Note 1621946 and SAP Note 1488500.
- Execute correction instructions: after applying the note via SNOTE, run the ABAP program
RITS_XSS_PARAM_BOS02using transaction SE38 or SA38. Provide a transport request when prompted and use it to move the changes across the system landscape.
Reason and prerequisites
Within IS-ADEC-BOQ, the ITS Services BOS02 and BOS02_WAP do not sufficiently encode OUTPUT parameters, leading to a cross-site scripting vulnerability. This vulnerability can be exploited to steal authentication information, potentially allowing an attacker to impersonate users, including administrators, thereby compromising the application’s security.
Affected components
- ECC-DIMP 500
- ECC-DIMP 600
- ECC-DIMP 602
- ECC-DIMP 603
- ECC-DIMP 604
- ECC-DIMP 605
- ECC-DIMP 606
Full note on SAP: SAP Support Launchpad note 1673131
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
