SAP security note 1597804, "Unauthorized modification of displayed content", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Pages within Web Channel applications do not sufficiently encode output parameters, resulting in a reflected cross-site scripting (XSS) issue. A reflected XSS attack can be used to non-permanently deface or modify displayed content on a website. Additionally, it can be used to steal another user’s authentication information, such as data relating to their current session. A malicious user who gains access to this data may impersonate the user and access all information with the same rights as the target user. If an administrator is impersonated, the security of the application may be fully compromised.
Solution
This note contains Java correction(s) for E-Commerce and Web Channel. Apply the Support Package patch level attached to this note. For more information about applying Java patches, refer to Note 877887. See Note 1546959 for information about the patch strategy.
If you are using Internet Service B2B/B2C or Claims and Returns web applications, do not allow the upload of HTML or JavaScript documents. Maintain the attachment component configuration in the application configurations of the web applications within the Extended Configuration Management (XCM) accordingly. Do not use the document types text/html and text/javascript for the parameter attachments_upload_file_type_filter.
Reason and prerequisites
The issue arises because Web Channel application pages do not properly encode output parameters, making them susceptible to reflected XSS attacks.
Side effects
This document is causing side effects in Log files not accessible from CRM-ISA admin logging page (1702925).
References
- Patch strategies for SAP E-Commerce solutions (1546959)
- Installing Patches for CRM Java Components and FSCM BD (877887)
Affected components
- SAP-CRMISA: 4.0_640
- SAP-CRMJAV: 5.0, 6.0, 700, 701, 730
- SAP-CRMWEB: 5.0, 6.0, 700, 701, 730
- SAP-SHRWEB: 5.0, 6.0, 700, 701, 730
- SAP-SHRJAV: 5.0, 6.0, 700, 701, 730
- SAP-CRMAPP: 5.0, 6.0, 700, 701, 730
- SAP-SHRAPP: 5.0, 6.0, 700, 701, 730
Full note on SAP: SAP Support Launchpad note 1597804
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
