Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in WebDynpro, SAP security note 1649117

SAP Note 1649117
SAP Security Note
High priority

SAP security note 1649117, "Unauthorized modification of displayed content in WebDynpro", is a note released on May 8, 2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Web Dynpro > Web Dynpro ABAP (BC-WD-ABA)
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onMay 8, 2012

Description

Symptom

Web Dynpro ABAP can be exploited by an attacker to modify displayed application content without authorization. This vulnerability may allow the attacker to obtain authentication information from other legitimate users.

Solution

Apply the appropriate service pack or correction instruction as detailed in this security note.

Reason and prerequisites

Applications and components within Web Dynpro ABAP do not sufficiently encode output parameters, resulting in a reflected cross-site scripting issue. An attacker can use this vulnerability to:

  • Non-permanently deface or modify displayed content on a website.
  • Steal a user’s authentication information, such as session data.
  • Impersonate users, including administrators, potentially compromising the entire application’s security.

CVSS

Score 0

Affected components

  • Basis Components > Web Dynpro > Web Dynpro ABAP (BC-WD-ABA)

Full note on SAP: SAP Support Launchpad note 1649117

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More