SAP security note 1618864, “Unauthorized modification of stored content in RWB”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability has been identified in the Message Content display within the Runtime Workbench (RWB). A malicious user can exploit this vulnerability to modify application content without authorization, leading to stored cross-site scripting (XSS) attacks. This can result in the embedding of malicious content, theft of authentication information, and the potential impersonation of users, including administrators, thereby compromising the application’s security.
Solution
To address this security vulnerability, it is essential to update the affected software components to the specified patch levels or newer versions. Follow these steps:
- Apply Support Package Patches: refer to the Support Package Patches section of this note to identify and apply the necessary patches for your system’s software components.
- Download Patches: Download for SNOTE, PDF Version.
- Verify Patch Installation: ensure that the patches have been correctly applied by checking the version numbers and validation through the SAP Support Marketplace.
For detailed instructions and additional information, visit the full SAP Security Note here.
References
- SAP Note 1718340 – Message Monitoring: High Heap Consumption for Payload Display
- SAP Note 1683900 – ESR, SR, UDDI, MESSAGING related changes in 7.11 SP09
- SAP Note 1683419 – ESR, MESSAGING, SR, UDDI related changes in 7.10 SP14
Affected components
- MESSAGING SYSTEM SERVICE: versions 7.10 to 7.31
Full note on SAP: SAP Support Launchpad note 1618864
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
