SAP Security Note
SAP security note 1857350, “Unauthorized modification of displayed content in BIW”, was released on July 9, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
BI Workspaces can be abused by an attacker, allowing them to modify displayed application content without authorization, and potentially obtain authentication information from other legitimate users.
Solution
Apply one of the following patches, according to the installed version:
- SAP BusinessObjects XI4.0 Patch4.15
- SAP BusinessObjects XI4.0 Patch5.9
- SAP BusinessObjects XI4.0 Patch6.1
- SAP BusinessObjects XI4.0 SP7 onwards
Reason and prerequisites
Pages within BI Workspaces do not sufficiently encode output parameters, resulting in a reflected cross-site scripting issue. An attacker can steal user authentication information, impersonate users, and potentially compromise the security of the application.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
Affected components
- Business intelligence solutions > Business intelligence platform > BI Workspaces (Dashboard Builder)
Full note on SAP: SAP Support Launchpad note 1857350
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




