SAP security note 1614834, "Unauthorized modification of displayed content in UDDIClient", is documented below with the symptom, SAP recommended solution and the affected software components.
Description
Symptom
UDDI Client BSP can be exploited by a malicious user, allowing unauthorized modification of displayed application content. This vulnerability may also enable attackers to obtain authentication information from legitimate users.
Solution
To address this vulnerability, apply the corresponding ABAP support package relevant to your SAP_BASIS version.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
References
- SAP Note 888889: Automatic checks for security notes using RSECNOTE (outdated)
- SAP Note 1749429: ESI – Error "The master language in source and target systems is different" when implementing SAP Security Note 1614834
Affected components
- SAP_BASIS 620 to 640, 700 to 702, 710 to 730, 731
Full note on SAP: SAP Support Launchpad note 1614834
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
