SAP Security Note
High priority
SAP security note 1655180, "Unauthorized change of displayed contents in CO-PC-PCP-REF", is a note released on January 10, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can exploit CO-PC-PCP-REF to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
Solution
Implement the attached program correction to mitigate the vulnerability.
Reason and prerequisites
Pages within CO-PC-PCP-REF do not sufficiently encode input parameters, resulting in a reflected XSS vulnerability. This flaw allows attackers to deface web content or steal user authentication information, which can lead to user impersonation and full compromise of application security.
Full note on SAP: SAP Support Launchpad note 1655180
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
