SAP security note 1600317, "Unauthorized Modification of Displayed Content in BSP", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability exists in BSP applications using HTMLB, XHTMLB, and PHTMLB tags that allows attackers to modify displayed application content without authorization. This can lead to the theft of authentication information from legitimate users, enabling attackers to impersonate users and potentially compromise the entire security of the application.
Solution
Apply SAP Security Note 1600317 using SNOTE to mitigate the vulnerability. This update ensures that output parameters are properly encoded, preventing reflected cross-site scripting attacks.
Affected components
- SAP_BASIS 620 – 640
- SAP_BASIS 700 – 702
- SAP_BASIS 710 – 730
- SAP_BASIS 731
Full note on SAP: SAP Support Launchpad note 1600317
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
