SAP security note 1637338, "Unauthorized modification of displayed content in UR", is documented below with the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Unified Rendering (UR) in SAP can be exploited to allow attackers to modify displayed application content without authorization. This vulnerability may enable the theft of authentication information from legitimate users through reflected cross-site scripting (XSS) attacks. Such attacks can lead to session hijacking, allowing attackers to impersonate users and gain unauthorized access to information and functionalities.
Solution
To address this security vulnerability, implement the following corrections:
- Apply the corrections provided in SAP Note 1637338.
- Additionally, ensure to review and apply framework-specific notes: HTMLB SAP Note 1653473, WD JAVA SAP Note 1653474.
References
- 1749777 – Unauthorized modification of content displayed in BW
- 1710779 – Adjustments in build dependencies
- 1708997 – Corrections for unified rendering 701/12 III (UR-Mimes)
- 1653474 – Unauthorized Modification of Displayed Content in Web Dynpro
- 1653473 – Unauthorized Modification of Displayed Content in HTMLB
- 1590008 – JAVA output encoding
Affected components
- Basis Components > Web Dynpro > Unified Rendering (BC-WD-UR)
Full note on SAP: SAP Support Launchpad note 1637338
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
