Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content, SAP security note 1597804

SAP Note 1597804

SAP security note 1597804, "Unauthorized modification of displayed content", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Pages within Web Channel applications do not sufficiently encode output parameters, resulting in a reflected cross-site scripting (XSS) issue. A reflected XSS attack can be used to non-permanently deface or modify displayed content on a website. Additionally, it can be used to steal another user’s authentication information, such as data relating to their current session. A malicious user who gains access to this data may impersonate the user and access all information with the same rights as the target user. If an administrator is impersonated, the security of the application may be fully compromised.

Solution

This note contains Java correction(s) for E-Commerce and Web Channel. Apply the Support Package patch level attached to this note. For more information about applying Java patches, refer to Note 877887. See Note 1546959 for information about the patch strategy.

If you are using Internet Service B2B/B2C or Claims and Returns web applications, do not allow the upload of HTML or JavaScript documents. Maintain the attachment component configuration in the application configurations of the web applications within the Extended Configuration Management (XCM) accordingly. Do not use the document types text/html and text/javascript for the parameter attachments_upload_file_type_filter.

Reason and prerequisites

The issue arises because Web Channel application pages do not properly encode output parameters, making them susceptible to reflected XSS attacks.

Side effects

This document is causing side effects in Log files not accessible from CRM-ISA admin logging page (1702925).

References

Affected components

  • SAP-CRMISA: 4.0_640
  • SAP-CRMJAV: 5.0, 6.0, 700, 701, 730
  • SAP-CRMWEB: 5.0, 6.0, 700, 701, 730
  • SAP-SHRWEB: 5.0, 6.0, 700, 701, 730
  • SAP-SHRJAV: 5.0, 6.0, 700, 701, 730
  • SAP-CRMAPP: 5.0, 6.0, 700, 701, 730
  • SAP-SHRAPP: 5.0, 6.0, 700, 701, 730

Full note on SAP: SAP Support Launchpad note 1597804

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More