Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in Business Workplace, SAP security note 1884596

SAP Note 1884596
High priority

SAP security note 1884596, "Stored Cross-Site Scripting Vulnerability in Business Workplace", was released on 14.01.2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBC-SRV-BTF (Business Text Framework)
PriorityCorrection with high priority
StatusReleased for Customer
Released on14.01.2014

Description

Symptom

SAP applications that display and process HTML documents are vulnerable to a stored Cross-Site Scripting (XSS) attack. An attacker can exploit this vulnerability to modify application content without authorization, persist the changes, and potentially steal authentication information from other users. This can lead to unauthorized access and compromise the security of the affected application.

Solution

To address this vulnerability, install the appropriate support package or implement the correction instructions provided in this SAP Security Note. This involves updating the filter functionality used by SAP applications that handle HTML documents to prevent unauthorized modifications and mitigate the risk of XSS attacks.

  • Ensure you are running one of the supported SAP_BASIS versions (620, 640, 700, 701, 702, 710, 711, 720, 730, 731, 740) and install the latest support packages.

CVSS

Score 3.5 Vector: AV:N/AC:M/AU:S/C:N/I:P/A:N

References

Affected components

  • SAP_BASIS 620 to 740

Full note on SAP: SAP Support Launchpad note 1884596

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More