Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in LOD-ESO-AS, SAP security note 1661734

SAP Note 1661734

SAP security note 1661734, “Unauthorized modification of stored content in LOD-ESO-AS”. Below are the symptom and SAP recommended solution.

Description

Symptom

LOD-ESO-AS can be abused by an attacker, allowing them to modify application content, persist the modified content without authorization, and potentially obtain authentication information from other legitimate users.

Solution

Fixes have been developed and released in the following versions:

  • Version 5.0 J
  • Version 5.1 Patch 10
  • All Version 7.0 SP and patch releases

To mitigate this risk, update to the appropriate release or patch version. You can download the fix using the SNOTE download link or view the PDF version of the note.

For more information, visit the SAP Support Portal.

Reason and prerequisites

Several pages in LOD-ESO-AS are vulnerable to a stored cross-site scripting (XSS) attack. This vulnerability can be exploited to:

  • Permanently modify displayed content on a website, allowing the attacker to embed malicious content that is rendered automatically without targeting victims individually.
  • Steal another user’s authentication information, such as data related to their current session. An attacker who gains access to this information may impersonate the user and access all information with the same rights as the target user. If an administrator is impersonated, the security of the entire application may be fully compromised.

Full note on SAP: SAP Support Launchpad note 1661734

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More