SAP security note 1828801, "Unauthorized modification of displayed content in SV-SMG-DIA-SRV". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Solution Manager internal support tools can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.
An attacker can exploit certain Solution Manager servlet-based pages that do not sufficiently encode input parameters, resulting in a potential cross-site scripting (XSS) issue. This can be used to non-permanently deface or modify displayed content from a web site and steal user authentication information.
Solution
The potential threat has been addressed and fixed with Solution Manager 7.1 SP05.
Reason and prerequisites
Certain Solution Manager servlet-based pages fail to adequately encode input parameters, leading to a potential XSS vulnerability. An attacker can use this to steal another user's authentication information, such as session data, enabling them to impersonate the user and access information with the same privileges.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
Affected components
- LM-SERVICE 7.10
Full note on SAP: SAP Support Launchpad note 1828801
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



